Command Injection Vulnerability in Jenkins Debian Package Builder Plugin
CVE-2022-23118
8.8HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 12 January 2022
What is CVE-2022-23118?
The Jenkins Debian Package Builder Plugin allows agents to invoke command-line git at a path determined by an attacker. If an attacker gains control over an agent process, they can execute arbitrary operating system commands on the Jenkins controller, leading to significant security risks.
Affected Version(s)
Jenkins Debian Package Builder Plugin <= 1.6.11