Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agent processes to invoke command-line git at an attacker-specified path on the controller.
This allows attackers able to control agent processes to invoke arbitrary OS commands on the controller.
{
"nvd_published_at": "2022-01-12T20:15:00Z",
"severity": "HIGH",
"github_reviewed_at": "2022-06-01T20:10:51Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-269",
"CWE-668",
"CWE-693"
]
}