CVE-2022-20617
jenkins-2-plugins/docker-commons: does not sanitize the name of an image or a tag which could result in an OS command execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM repository.
Jenkins Docker Commons Plugin versiones 1.17 y anteriores, no sanea el nombre de una imagen o una etiqueta, resultando en una vulnerabilidad de ejecución de comandos del Sistema Operativo explotable por atacantes con permiso Item/Configure o capaces de controlar el contenido del repositorio SCM de un trabajo previamente configurado
An OS command execution vulnerability was found in the Jenkins Docker Commons plugin. Due to a lack of sanitization in the name of an image or a tag, an attacker with Item/Configure permission or the ability to control the contents of a previously configured job’s SCM repository may be able to execute OS commands.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-10-28 CVE Reserved
- 2022-01-12 CVE Published
- 2024-07-23 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2022/01/12/6 | 2023-11-22 | |
https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-1878 | 2023-11-22 | |
https://access.redhat.com/security/cve/CVE-2022-20617 | 2022-02-25 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2044502 | 2022-02-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jenkins Search vendor "Jenkins" | Docker Commons Search vendor "Jenkins" for product "Docker Commons" | <= 1.17 Search vendor "Jenkins" for product "Docker Commons" and version " <= 1.17" | jenkins |
Affected
|