CVE-2022-27201: Medium severity jenkins semantic versioning vulnerability
Jenkins Semantic Versioning Plugin 1.13 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitations about the file path that can be parsed, allowing attackers able to control agent processes to have Jenkins parse a crafted file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Jenkins issue?
The vulnerability ID of this Jenkins issue is CVE-2022-27201.
What is the title of this Jenkins vulnerability?
The title of this Jenkins vulnerability is 'Jenkins Semantic Versioning Plugin 1.13 and earlier does not restrict execution of an controller/agent message'.
What is the severity rating of CVE-2022-27201?
The severity rating of CVE-2022-27201 is medium, with a CVSS score of 6.5.
What software versions are affected by CVE-2022-27201?
Jenkins Semantic Versioning Plugin 1.13 and earlier versions are affected by CVE-2022-27201.
How can attackers exploit CVE-2022-27201?
Attackers who can control agent processes can exploit CVE-2022-27201 by having Jenkins parse a crafted file.