CVE-2022-25174
HIGHJenkins Pipeline < 552.vd9cc05b8a2e1 - Authenticated OS Command Injection via SCM Checkout Directory
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-25174. PoCs published by shoucheng3.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2022-25174, targeting Jenkins Pipeline Shared Libraries. The exploit leverages insecure class loading and Groovy script execution to achieve remote code execution (RCE).
Description
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
Exploits (1)
This repository contains a proof-of-concept exploit for CVE-2022-25174, targeting Jenkins Pipeline Shared Libraries. The exploit leverages insecure class loading and Groovy script execution to achieve remote code execution (RCE).
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H