Script Security Vulnerability in Jenkins Plugin by Jenkins
CVE-2022-45379
7.5HIGH
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 15 November 2022
What is CVE-2022-45379?
The Jenkins Script Security Plugin prior to version 1189.vb_a_b_7c8fd5fde is susceptible to security risks due to the storage method of script approvals. It utilizes the SHA-1 hash of the whole-script approvals, which opens the door to potential collision attacks, enabling malicious actors to craft scripts capable of bypassing security measures. Organizations using this plugin should ensure they update to the latest version to mitigate these vulnerabilities.
Affected Version(s)
Jenkins Script Security Plugin <= 1189.vb_a_b_7c8fd5fde
Jenkins Script Security Plugin 1175.1179.vea_f7532629e1