CVE-2022-25173: OS Command Injection
A flaw was found in Jenkins. The Pipeline: Groovy Plugin uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines. This flaw allows attackers with item/configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
Other sources
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
Jenkins Pipeline: Groovy Plugin prior to 2656.vf7ae7b75a457, 2.94.1, and 2.92.1 uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines. This allows attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
References:
https://www.jenkins.io/security/advisory/2022-02-15/
— Red Hat
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-25173?
CVE-2022-25173 is classified as a high severity vulnerability due to its potential to allow attackers to execute arbitrary OS commands.
How do I fix CVE-2022-25173?
To fix CVE-2022-25173, upgrade Jenkins to version 2.92.1 or later, or ensure you are using a patched version of the affected plugins.
What software is affected by CVE-2022-25173?
CVE-2022-25173 affects Jenkins with the Pipeline: Groovy Plugin, particularly versions prior to 2.92.1.
What kind of permission do attackers need to exploit CVE-2022-25173?
An attacker needs item/configure permission to exploit CVE-2022-25173 and invoke arbitrary OS commands.
Where can I find more information about CVE-2022-25173?
More information about CVE-2022-25173 can typically be found in security advisories or the official Jenkins security page.