CVE-2022-29047

MEDIUM

Jenkins Pipeline: Shared Groovy Libraries Plugin <2.21.3 - Code Inj...

Title source: llm
STIX 2.1

Description

Jenkins Pipeline: Shared Groovy Libraries Plugin 564.ve62a_4eb_b_e039 and earlier, except 2.21.3, allows attackers able to submit pull requests (or equivalent), but not able to commit directly to the configured SCM, to effectively change the Pipeline behavior by changing the definition of a dynamically retrieved library in their pull request, even if the Pipeline is configured to not trust them.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0008
EPSS Percentile 24.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
jenkins/pipeline\ < 2.21.3
org.jenkins-ci.plugins.workflow/workflow-cps-global-lib 0 - 2.21.3Maven
Published Apr 12, 2022
Tracked Since Feb 18, 2026