GHSA-2m9w-9xh2-wxc3

Suggest an improvement
Source
https://github.com/advisories/GHSA-2m9w-9xh2-wxc3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-2m9w-9xh2-wxc3/GHSA-2m9w-9xh2-wxc3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2m9w-9xh2-wxc3
Aliases
  • CVE-2022-25179
Published
2022-02-16T00:01:33Z
Modified
2023-11-08T04:08:42.318145Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Link Following in Jenkins Pipeline Multibranch Plugin
Details

Jenkins Pipeline: Multibranch Plugin prior to 2.23.1, 2.26.1, 696.698.v9b4218eea50f, and 707.v71c3f0a6ccdb follows symbolic links to locations outside of the checkout directory for the configured SCM when reading files using the readTrusted step, allowing attackers able to configure Pipelines permission to read arbitrary files on the Jenkins controller file system.

Database specific
{
    "nvd_published_at": "2022-02-15T17:15:00Z",
    "cwe_ids": [
        "CWE-59"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2022-02-25T20:40:40Z"
}
References

Affected packages

Maven / org.jenkins-ci.plugins.workflow:workflow-multibranch

Package

Name
org.jenkins-ci.plugins.workflow:workflow-multibranch
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins.workflow/workflow-multibranch

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.24
Fixed
2.26.1

Affected versions

2.*

2.24
2.25
2.26

Maven / org.jenkins-ci.plugins.workflow:workflow-multibranch

Package

Name
org.jenkins-ci.plugins.workflow:workflow-multibranch
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins.workflow/workflow-multibranch

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.23.1

Affected versions

1.*

1.9-beta-1
1.9-beta-2
1.11-beta-1
1.11-beta-2
1.11-beta-3
1.11
1.12-beta-1
1.12-beta-2
1.12-beta-3
1.12
1.13
1.14-beta-1
1.14
1.14.1-beta-1
1.14.1
1.14.2
1.15-beta-1
1.15

2.*

2.0
2.1
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2.9.1
2.9.2
2.10-beta-1
2.10
2.11-beta-1
2.11
2.12
2.13
2.14
2.15
2.16
2.17
2.17-durability-beta-1
2.17-durability-beta-2
2.18
2.19
2.20
2.21
2.22
2.23

Maven / org.jenkins-ci.plugins.workflow:workflow-multibranch

Package

Name
org.jenkins-ci.plugins.workflow:workflow-multibranch
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins.workflow/workflow-multibranch

Affected ranges

Type
ECOSYSTEM
Events
Introduced
696.v52535c46f4c9
Fixed
696.698.v9b4218eea50f

Affected versions

696.*

696.v52535c46f4c9

Maven / org.jenkins-ci.plugins.workflow:workflow-multibranch

Package

Name
org.jenkins-ci.plugins.workflow:workflow-multibranch
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins.workflow/workflow-multibranch

Affected ranges

Type
ECOSYSTEM
Events
Introduced
706.vd43c65dec013
Fixed
707.v71c3f0a

Affected versions

706.*

706.vd43c65dec013