First published: Tue Nov 15 2022(Updated: )
A flaw was found in the Pipeline Utility Steps Jenkins Plugin. The affected version of the Pipeline Utility Steps Plugin does not restrict the set of enabled prefix interpolators and bundles versions of this library that enable the file: prefix interpolator by default. This flaw allows attackers who can configure Pipelines to read arbitrary files from the Jenkins controller file system.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jenkins | <2-plugins-0:4.10.1675144701-1.el8 | 2-plugins-0:4.10.1675144701-1.el8 |
redhat/jenkins | <2-plugins-0:4.9.1675668922-1.el8 | 2-plugins-0:4.9.1675668922-1.el8 |
Jenkins Pipeline Utility Steps | <2.13.2 | |
<2.13.2 | ||
redhat/Pipeline Utility Steps Plugin | <2.13.2 | 2.13.2 |
maven/org.jenkins-ci.plugins:pipeline-utility-steps | <=2.13.1 | 2.13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45381 is classified as a high severity vulnerability due to its potential to allow attackers to exploit the file: prefix interpolator.
To fix CVE-2022-45381, upgrade to Pipeline Utility Steps Plugin version 2.13.2 or later.
CVE-2022-45381 affects versions of the Pipeline Utility Steps Plugin prior to 2.13.2.
CVE-2022-45381 affects the Jenkins Pipeline Utility Steps Plugin and certain related Jenkins packages.
A workaround for CVE-2022-45381 is to disable the file: prefix interpolator in the affected versions.