cbcvebase.
CVE-2022-23107
published 2022-01-12

CVE-2022-23107: Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with…

high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the Jenkins controller file system.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsactive_directory_plugin
jenkinsbadge_plugin
jenkinsbitbucket_branch_source_plugin
jenkinsconfiguration_as_code_plugin
jenkinsconjur_secrets_plugin
jenkinscredentials_binding_plugin
jenkinscredentials_plugin
jenkinsdebian_package_builder_plugin
jenkinsdocker_commons_plugin
jenkinsgroovy_plugin
jenkinshashicorp_vault_plugin
jenkinsids_in_bitbucket_branch_source_plugin
jenkinsimproper_credentials_masking_in_hashicorp_vault_plugin
jenkinsjenkins_core
jenkinsjenkins_lts
jenkinsjenkins_ui_requesting_they_update_the_plugin
jenkinsjenkins_weekly
jenkinsmailer_plugin
jenkinsmatrix_project_plugin
jenkinsmetrics_plugin
jenkinspublish_over_ssh_plugin
jenkinsssh_agent_plugin
jenkinswarnings_next_generation
jenkinswarnings_next_generation>= 9.0.0 < 9.0.29.0.2
jenkinswarnings_next_generation9.10.0 – 9.10.2