Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0893 | A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller JVM using specially crafted library names if a global Pipeline library is already configured. |
Github GHSA |
GHSA-7rcw-fwfh-2h2g | Jenkins Pipeline: Deprecated Groovy Libraries Plugin Protection Mechanism Failure |
Tue, 19 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-11-19T19:28:36.784Z
Reserved: 2022-02-15T00:00:00.000Z
Link: CVE-2022-25182
Updated: 2024-08-03T04:36:05.826Z
Status : Modified
Published: 2022-02-15T17:15:09.120
Modified: 2024-11-21T06:51:45.887
Link: CVE-2022-25182
OpenCVE Enrichment
No data.
EUVD
Github GHSA