{"id":"GHSA-8xjp-rp29-v5j8","summary":"Agent-to-controller security bypass in Jenkins Debian Package Builder Plugin","details":"Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agent processes to invoke command-line git at an attacker-specified path on the controller.\n\nThis allows attackers able to control agent processes to invoke arbitrary OS commands on the controller.","aliases":["CVE-2022-23118"],"modified":"2024-02-16T08:16:38.081470Z","published":"2022-01-13T00:00:52Z","database_specific":{"nvd_published_at":"2022-01-12T20:15:00Z","cwe_ids":["CWE-269","CWE-668","CWE-693"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-06-01T20:10:51Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23118"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/debian-package-builder-plugin"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2022-01-12/#SECURITY-2546"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/01/12/6"}],"affected":[{"package":{"name":"ru.yandex.jenkins.plugins.debuilder:debian-package-builder","ecosystem":"Maven","purl":"pkg:maven/ru.yandex.jenkins.plugins.debuilder/debian-package-builder"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.6.11"}]}],"versions":["1.2","1.3","1.4","1.4.1","1.4.2","1.5.1","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.6.0","1.6.1","1.6.10","1.6.11","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.6.7","1.6.8","1.6.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-8xjp-rp29-v5j8/GHSA-8xjp-rp29-v5j8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}