CVE-2022-25174: OS Command Injection
A flaw was found in Jenkins. The JenkinsPipeline: Shared Groovy Libraries uses the same checkout directories for distinct SCMs for Pipeline libraries. This flaw allows attackers with item/configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents. This allows attackers to compromise confidentiality, integrity, and availability.
Other sources
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
Jenkins Pipeline: Shared Groovy Libraries Plugin prior to 561.vace0de3c2d69, 2.21.1, and 2.18.1 uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
Pipeline: Shared Groovy Libraries 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libraries. This allows attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
— Red Hat
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-25174?
CVE-2022-25174 has a high severity rating due to its potential to allow arbitrary OS command execution on the Jenkins controller.
How do I fix CVE-2022-25174?
To fix CVE-2022-25174, upgrade to the recommended patched versions of the Jenkins Pipeline or the affected plugins.
What are the affected Jenkins versions for CVE-2022-25174?
CVE-2022-25174 affects several versions of Jenkins, particularly those with shared Groovy libraries using the same checkout directories.
Can CVE-2022-25174 be exploited remotely?
Yes, CVE-2022-25174 can be exploited by attackers with item/configure permissions, which may potentially lead to remote code execution.
What kind of permissions are required to exploit CVE-2022-25174?
Exploitation of CVE-2022-25174 requires attackers to have item/configure permissions on the Jenkins controller.