CVE-2022-20617
12.01.2022, 20:15
Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM repository.
Vendor | Product | Version |
---|---|---|
jenkins | docker_commons | 𝑥 ≤ 1.17 |
𝑥
= Vulnerable software versions