First published: Wed Jan 12 2022(Updated: )
Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller, allowing attackers able to control agent processes to invoke arbitrary OS commands on the controller.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Debian Package Builder | <=1.6.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-23118.
The severity of CVE-2022-23118 is critical with a score of 8.8.
The affected software is Jenkins Debian Package Builder Plugin version 1.6.11 and earlier.
CVE-2022-23118 allows attackers with control over agent processes to invoke arbitrary OS commands on the controller of Jenkins Debian Package Builder Plugin.
The fix for CVE-2022-23118 is to update Jenkins Debian Package Builder Plugin to a version that is later than 1.6.11.