CVE-2022-25175
HIGHJenkins Pipeline Multibranch < 706.vd43c65dec013 - Authenticated OS Command Injection via readTrusted Step
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-25175. PoCs published by shoucheng3.
AI-analyzed exploit summary This repository contains source code and documentation for the Jenkins Pipeline Multibranch plugin, specifically addressing CVE-2022-25175. The provided files include Java source code for the plugin's functionality and a README with general plugin information, but no exploit PoC or offensive techniques are present.
Description
Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
Exploits (1)
This repository contains source code and documentation for the Jenkins Pipeline Multibranch plugin, specifically addressing CVE-2022-25175. The provided files include Java source code for the plugin's functionality and a README with general plugin information, but no exploit PoC or offensive techniques are present.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H