File Upload Vulnerability in Jenkins Deployer Framework Plugin by Jenkins
CVE-2022-36889

8.8HIGH

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
27 July 2022

Summary

The Jenkins Deployer Framework Plugin allows attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller's file system to a targeted service due to a lack of application path restrictions during deployment configuration. This vulnerability could lead to unauthorized access or malicious actions within the Jenkins environment, highlighting the necessity for proper permissions and security measures.

Affected Version(s)

Jenkins Deployer Framework Plugin <= 85.v1d1888e8c021

Jenkins Deployer Framework Plugin 1.3.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.