{"id":"GHSA-pj84-qjm3-77mg","summary":"Jenkins Pipeline: Multibranch Plugin vulnerable to OS Command Injection","details":"Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses distinct checkout directories per SCM for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.","aliases":["CVE-2022-25175"],"modified":"2024-02-16T08:09:09.598186Z","published":"2022-02-16T00:01:36Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-06-20T22:46:22Z","nvd_published_at":"2022-02-15T17:15:00Z","cwe_ids":["CWE-78"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25175"},{"type":"WEB","url":"https://github.com/jenkinsci/workflow-multibranch-plugin/commit/71c3f0a6ccdb2ba43f43686826b0d62160df85e8"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2463"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins.workflow:workflow-multibranch","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins.workflow/workflow-multibranch"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"707.v71c3f0a_6ccdb"}]}],"versions":["1.11","1.11-beta-1","1.11-beta-2","1.11-beta-3","1.12","1.12-beta-1","1.12-beta-2","1.12-beta-3","1.13","1.14","1.14-beta-1","1.14.1","1.14.1-beta-1","1.14.2","1.15","1.15-beta-1","1.9-beta-1","1.9-beta-2","2.0","2.1","2.10","2.10-beta-1","2.11","2.11-beta-1","2.12","2.13","2.14","2.15","2.16","2.17","2.17-durability-beta-1","2.17-durability-beta-2","2.18","2.19","2.2","2.20","2.21","2.22","2.23","2.23.1","2.24","2.25","2.26","2.26.1","2.3","2.4","2.5","2.6","2.7","2.8","2.9","2.9.1","2.9.2","696.698.v9b4218eea50f","696.v52535c46f4c9","704.v8f039a_e2e8cf","706.vd43c65dec013"],"database_specific":{"last_known_affected_version_range":"\u003c= 706.vd43c65dec013","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-pj84-qjm3-77mg/GHSA-pj84-qjm3-77mg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}