cbcvebase.
CVE-2022-29049
published 2022-04-12

CVE-2022-29049: Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the names of promotions defined in Job DSL, allowing attackers…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the names of promotions defined in Job DSL, allowing attackers with Job/Configure permission to create a promotion with an unsafe name.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
jenkinsbuild_step_plugin
jenkinscoordinator_plugin
jenkinscredentials_plugin
jenkinscvs_plugin
jenkinsdeprecated_groovy_libraries_plugin
jenkinsextended_choice_parameter_plugin
jenkinsgerrit_trigger_plugin
jenkinsgit_parameter_plugin
jenkinsgoogle_compute_engine_plugin
jenkinsinput_step_plugin
jenkinsjira_plugin
jenkinsjob_dsl_plugin
jenkinsjob_generator_plugin
jenkinsmask_passwords_plugin
jenkinsmaven_release_plugin
jenkinsnode_and_label_parameter_plugin
jenkinspromoted_builds< 3.10.13.10.1
jenkinspromoted_builds>= 867.v7c3a_b_83a_eb_79 < 876.v99d29788b_36b_876.v99d29788b_36b_
jenkinspromotion_names_in_promoted_builds_plugin
jenkinspublish_over_ftp_plugin
jenkinsrebuilder_plugin
jenkinsrelease_plugin
jenkinsshow_build_parameters_plugin
jenkinssubversion_plugin
jenkinsunleash_maven_plugin