First published: Tue Feb 15 2022(Updated: )
A flaw was found in Jenkins. The Pipeline: Shared Groovy Libraries plugin uses the names of Pipeline libraries to create cache directories without any sanitization. This flaw allows attackers with item/configure permission to execute arbitrary code in the context of the Jenkins controller JVM, using specially crafted library names if a global Pipeline library configured to use caching already exists.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jenkins | <2-plugins-0:3.11.1650371376-1.el7 | 2-plugins-0:3.11.1650371376-1.el7 |
redhat/jenkins | <2-plugins-0:4.10.1647505461-1.el8 | 2-plugins-0:4.10.1647505461-1.el8 |
redhat/jenkins | <2-plugins-0:4.6.1650364520-1.el8 | 2-plugins-0:4.6.1650364520-1.el8 |
redhat/jenkins | <2-plugins-0:4.7.1648800585-1.el8 | 2-plugins-0:4.7.1648800585-1.el8 |
redhat/jenkins | <2-plugins-0:4.8.1646993358-1.el8 | 2-plugins-0:4.8.1646993358-1.el8 |
redhat/jenkins | <2-plugins-0:4.9.1647580879-1.el8 | 2-plugins-0:4.9.1647580879-1.el8 |
Jenkins Pipeline\ | <=552.vd9cc05b8a2e1 | |
maven/org.jenkins-ci.plugins.workflow:workflow-cps-global-lib | <=552.vd9cc05b8a2e1 | 561.va_ce0de3c2d69 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-25183 is considered a high severity vulnerability due to the potential for arbitrary code execution in the Jenkins controller JVM.
To mitigate CVE-2022-25183, update the Pipeline: Shared Groovy Libraries plugin to a version that incorporates security enhancements.
CVE-2022-25183 affects multiple versions of Jenkins, particularly those prior to the patched versions provided in the Red Hat packages.
Yes, CVE-2022-25183 can be exploited by attackers with item/configure permissions, allowing remote code execution.
Users with item/configure permissions in Jenkins are at risk due to the vulnerability presented in CVE-2022-25183.