CVE-2022-23118
EUVD-2022-053612.01.2022, 20:15
Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller, allowing attackers able to control agent processes to invoke arbitrary OS commands on the controller.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jenkins | debian_package_builder | 𝑥 ≤ 1.6.11 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration