CVE-2023-28677

CRITICAL

Jenkins Convert To Pipeline Plugin <1.0 - RCE

Title source: llm
STIX 2.1

Description

Jenkins Convert To Pipeline Plugin 1.0 and earlier uses basic string concatenation to convert Freestyle projects' Build Environment, Build Steps, and Post-build Actions to the equivalent Pipeline step invocations, allowing attackers able to configure Freestyle projects to prepare a crafted configuration that injects Pipeline script code into the (unsandboxed) Pipeline resulting from a convertion by Jenkins Convert To Pipeline Plugin.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0196
EPSS Percentile 83.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-77
Status published
Products (2)
jenkins/convert_to_pipeline < 1.0
org.jenkins-ci.plugins/convert-to-pipeline 0Maven
Published Apr 02, 2023
Tracked Since Feb 18, 2026