CVE-2022-45381

HIGH

Jenkins Pipeline Utility Steps < 2.13.2 - Arbitrary File Read via Apache Commons Configuration Interpolator

Title source: llm
STIX 2.1

Description

Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and bundles versions of Apache Commons Configuration library that enable the 'file:' prefix interpolator by default, allowing attackers able to configure Pipelines to read arbitrary files from the Jenkins controller file system.

References (2)

Core 2

Scores

CVSS v3 8.1
EPSS 0.0031
EPSS Percentile 54.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
jenkins/pipeline_utility_steps < 2.13.2
org.jenkins-ci.plugins/pipeline-utility-steps 0 - 2.13.2Maven
Published Nov 15, 2022
Tracked Since Feb 18, 2026