CVE-2022-28156
published 2022-03-29CVE-2022-28156: Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to copy arbitrary files and directories from the…
medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to copy arbitrary files and directories from the Jenkins controller to the agent workspace.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | bitbucket_server_integration_plugin | — | — |
| jenkins | complexity_scatter_plot_plugin | — | — |
| jenkins | continuous_integration_with_toad_edge_plugin | — | — |
| jenkins | flaky_test_handler_plugin | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jiratestresultreporter_plugin | — | — |
| jenkins | job_and_node_ownership_plugin | — | — |
| jenkins | phoenix_autotest_plugin | — | — |
| jenkins | pipeline | <= 1.3 | — |
| jenkins | proxmox_plugin | — | — |
| jenkins | rocketchat_notifier_plugin | — | — |
| jenkins | sitemonitor_plugin | — | — |
| jenkins | some_reports_generated_by_this_plugin | — | — |
| jenkins | tests_selector_plugin | — | — |
| jenkins | windows_in_continuous_integration_with_toad_edge_plugin | — | — |
| jenkins_project | jenkins_pipeline_phoenix_autotest_plugin | unspecified – 1.3 | — |