9
CVSSv2

CVE-2022-23118

Published: 12/01/2022 Updated: 30/11/2023
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 802
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Jenkins Debian Package Builder Plugin 1.6.11 and previous versions implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller, allowing attackers able to control agent processes to invoke arbitrary OS commands on the controller.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins debian package builder