File Upload Vulnerability in Jenkins Deployer Framework Plugin by Jenkins
CVE-2022-36889
8.8HIGH
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 27 July 2022
Summary
The Jenkins Deployer Framework Plugin allows attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller's file system to a targeted service due to a lack of application path restrictions during deployment configuration. This vulnerability could lead to unauthorized access or malicious actions within the Jenkins environment, highlighting the necessity for proper permissions and security measures.
Affected Version(s)
Jenkins Deployer Framework Plugin <= 85.v1d1888e8c021
Jenkins Deployer Framework Plugin 1.3.1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved