CVE-2022-28156: Path Traversal
Published Mar 29, 2022
·Updated
Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to copy arbitrary files and directories from the Jenkins controller to the agent workspace.
Affected Software
1 affected component
Jenkins Pipeline\<=1.3
Event History
Mar 29, 2022
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-28156?
CVE-2022-28156 is considered a high severity vulnerability due to its potential for arbitrary file manipulation.
2
How do I fix CVE-2022-28156?
To fix CVE-2022-28156, update the Phoenix AutoTest Plugin to version 1.4 or later.
3
Who is affected by CVE-2022-28156?
CVE-2022-28156 affects Jenkins users with the Pipeline: Phoenix AutoTest Plugin version 1.3 or earlier.
4
What permissions are required to exploit CVE-2022-28156?
Exploitation of CVE-2022-28156 requires Item/Configure permissions on the Jenkins server.
5
What types of files can be copied due to CVE-2022-28156?
Due to CVE-2022-28156, attackers can copy arbitrary files and directories from the Jenkins controller to the agent workspace.