Jenkins Pipeline: Multibranch Plugin vulnerable to OS Command Injection
High severity
GitHub Reviewed
Published
Feb 16, 2022
to the GitHub Advisory Database
•
Updated Dec 28, 2023
Package
Affected versions
<= 706.vd43c65dec013
Patched versions
707.v71c3f0a_6ccdb
Description
Published by the National Vulnerability Database
Feb 15, 2022
Published to the GitHub Advisory Database
Feb 16, 2022
Reviewed
Jun 20, 2022
Last updated
Dec 28, 2023
Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses distinct checkout directories per SCM for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
References