GHSA-8xjp-rp29-v5j8

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-8xjp-rp29-v5j8/GHSA-8xjp-rp29-v5j8.json
Aliases
  • CVE-2022-23118
Published
2022-01-13T00:00:52Z
Modified
2023-04-11T01:49:57.234386Z
Details

Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line git at an attacker-specified path on the controller, allowing attackers able to control agent processes to invoke arbitrary OS commands on the controller.

References

Affected packages

Maven / ru.yandex.jenkins.plugins.debuilder:debian-package-builder

ru.yandex.jenkins.plugins.debuilder:debian-package-builder

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0
Last affected
1.6.11

Affected versions

1.*

1.2
1.3
1.4
1.4.1
1.4.2
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.6.0
1.6.1
1.6.10
1.6.11
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9