CVE-2023-28677: Command Injection
Jenkins Convert To Pipeline Plugin 1.0 and earlier uses basic string concatenation to convert Freestyle projects' Build Environment, Build Steps, and Post-build Actions to the equivalent Pipeline step invocations, allowing attackers able to configure Freestyle projects to prepare a crafted configuration that injects Pipeline script code into the (unsandboxed) Pipeline resulting from a convertion by Jenkins Convert To Pipeline Plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28677?
CVE-2023-28677 is classified as a medium severity vulnerability.
How do I fix CVE-2023-28677?
To fix CVE-2023-28677, upgrade the Jenkins Convert To Pipeline Plugin to version 1.1 or later.
What does CVE-2023-28677 affect?
CVE-2023-28677 affects Jenkins Convert To Pipeline Plugin version 1.0 and earlier.
What type of vulnerability is CVE-2023-28677?
CVE-2023-28677 is a vulnerability that involves inadequate string handling through basic string concatenation.
Who is impacted by CVE-2023-28677?
Users with configured Freestyle projects in Jenkins that utilize the Convert To Pipeline Plugin are impacted by CVE-2023-28677.