CVE-2022-45379

CWE-326CWE-3286 documents6 sources
Severity
7.5HIGH
EPSS
0.3%
top 44.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15
Latest updateNov 16

Description

Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the script, making it vulnerable to collision attacks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Mavenorg.jenkins-ci.plugins:script-security< 1190.v65867a_a_47126
CVEListV5jenkins_project/jenkins_script_security_pluginunspecified1189.vb_a_b_7c8fd5fde
NVDjenkins/script_security< 1190.v65867a_a_47126

🔴Vulnerability Details

3
OSV
Whole-script approval in Jenkins Script Security Plugin vulnerable to SHA-1 collisions2022-11-16
GHSA
Whole-script approval in Jenkins Script Security Plugin vulnerable to SHA-1 collisions2022-11-16
CVEList
CVE-2022-45379: Jenkins Script Security Plugin 11892022-11-15

📋Vendor Advisories

2
Jenkins
Jenkins Security Advisory 2022-11-152022-11-15
Red Hat
jenkins-plugin/script-security: Whole-script approval in Script Security Plugin vulnerable to SHA-1 collisions2022-11-15
CVE-2022-45379 (HIGH CVSS 7.5) | Jenkins Script Security Plugin 1189 | cvebase.io