Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agent processes to invoke command-line git at an attacker-specified path on the controller.
This allows attackers able to control agent processes to invoke arbitrary OS commands on the controller.
{ "nvd_published_at": "2022-01-12T20:15:00Z", "cwe_ids": [ "CWE-269", "CWE-668", "CWE-693" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-06-01T20:10:51Z" }