CVE-2023-28677: Command Injection

Published Mar 23, 2023
·
Updated

Jenkins Convert To Pipeline Plugin 1.0 and earlier uses basic string concatenation to convert Freestyle projects' Build Environment, Build Steps, and Post-build Actions to the equivalent Pipeline step invocations, allowing attackers able to configure Freestyle projects to prepare a crafted configuration that injects Pipeline script code into the (unsandboxed) Pipeline resulting from a convertion by Jenkins Convert To Pipeline Plugin.

Affected Software

1 affected component
Jenkins Convert To Pipeline Jenkins<=1.0

Event History

Mar 23, 2023
CVE Published
via MITRE·11:26 AM
Data Sourced
via MITRE·11:26 AM
Description
Apr 2, 2023
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2023-28677?

CVE-2023-28677 is classified as a medium severity vulnerability.

2

How do I fix CVE-2023-28677?

To fix CVE-2023-28677, upgrade the Jenkins Convert To Pipeline Plugin to version 1.1 or later.

3

What does CVE-2023-28677 affect?

CVE-2023-28677 affects Jenkins Convert To Pipeline Plugin version 1.0 and earlier.

4

What type of vulnerability is CVE-2023-28677?

CVE-2023-28677 is a vulnerability that involves inadequate string handling through basic string concatenation.

5

Who is impacted by CVE-2023-28677?

Users with configured Freestyle projects in Jenkins that utilize the Convert To Pipeline Plugin are impacted by CVE-2023-28677.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203