CVE-2022-36889

CWE-22Path Traversal5 documents5 sources
Severity
8.8HIGH
EPSS
0.5%
top 35.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27
Latest updateJul 28

Description

Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller file system to the selected service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

Mavenorg.jenkins-ci.plugins:deployer-framework< 86.v7b_a_4a_55b_f3ec
CVEListV5jenkins_project/jenkins_deployer_framework_pluginunspecified85.v1d1888e8c021
NVDjenkins/deployer_framework85.v1d1888e8c021

🔴Vulnerability Details

3
OSV
Jenkins Deployer Framework Plugin does not restrict application path of applications when configuring a deployment2022-07-28
GHSA
Jenkins Deployer Framework Plugin does not restrict application path of applications when configuring a deployment2022-07-28
CVEList
CVE-2022-36889: Jenkins Deployer Framework Plugin 852022-07-27

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2022-07-272022-07-27
CVE-2022-36889 (HIGH CVSS 8.8) | Jenkins Deployer Framework Plugin 8 | cvebase.io