CVE-2022-20617: OS Command Injection
Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM repository.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20617?
CVE-2022-20617 has a high severity level due to its capability for OS command execution.
How do I fix CVE-2022-20617?
To fix CVE-2022-20617, upgrade the Jenkins Docker Commons Plugin to version 1.18 or later.
Who is affected by CVE-2022-20617?
Users with Item/Configure permission or those who can control the contents of a job's SCM repository are potentially at risk.
What versions of Jenkins Docker Commons are vulnerable to CVE-2022-20617?
Jenkins Docker Commons Plugin versions 1.17 and earlier are vulnerable to CVE-2022-20617.
What types of attacks can exploit CVE-2022-20617?
CVE-2022-20617 can be exploited to execute arbitrary OS commands in a Jenkins environment.