CVE-2022-25174

CVE-2022-25174

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

Source: CVE-2022-25174

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다