Skip to main content

Vendor/product archive

jenkins / pipeline:shared_groovy_libraries CVEs

Beta · best-effort

7 CVEs tagged to jenkins / pipeline:shared_groovy_libraries0 Critical, 4 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2022-25183

Published Feb 15, 2022

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories without any sanitization, allowing…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25182

Published Feb 15, 2022

A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure permission to execute arbitra…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25181

Published Feb 15, 2022

A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure permission to execute arbitra…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25178

Published Feb 15, 2022

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier does not restrict the names of resources passed to the libraryResource step, allowing attackers able…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25177

Published Feb 15, 2022

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier follows symbolic links to locations outside of the expected Pipeline library when reading files usin…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25174

Published Feb 15, 2022

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1