CVE-2022-28157
published 2022-03-29CVE-2022-28157: Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller…
medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller via FTP to an attacker-specified FTP server.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | bitbucket_server_integration_plugin | — | — |
| jenkins | complexity_scatter_plot_plugin | — | — |
| jenkins | continuous_integration_with_toad_edge_plugin | — | — |
| jenkins | flaky_test_handler_plugin | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jiratestresultreporter_plugin | — | — |
| jenkins | job_and_node_ownership_plugin | — | — |
| jenkins | phoenix_autotest_plugin | — | — |
| jenkins | pipeline | <= 1.3 | — |
| jenkins | proxmox_plugin | — | — |
| jenkins | rocketchat_notifier_plugin | — | — |
| jenkins | sitemonitor_plugin | — | — |
| jenkins | some_reports_generated_by_this_plugin | — | — |
| jenkins | tests_selector_plugin | — | — |
| jenkins | windows_in_continuous_integration_with_toad_edge_plugin | — | — |
| jenkins_project | jenkins_pipeline_phoenix_autotest_plugin | unspecified – 1.3 | — |