CVE-2022-20617

Related Vulnerabilities: CVE-2022-20617  

Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM repository.

Description

The MITRE CVE dictionary describes this issue as:

Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM repository.

Additional Information

  • Bugzilla 2044502: CVE-2022-20617 jenkins-2-plugins/docker-commons: does not sanitize the name of an image or a tag which could result in an OS command execution
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  • FAQ: Frequently asked questions about CVE-2022-20617