CVE-2022-34193
Es existieren mehrere Schwachstellen in Jenkins Core und verschiedenen Plugins. Zu diesen Plugins gehören: Agent Server Parameter Plugin, Beaker builder Plugin, Convertigo Mobile Platform Plugin, CRX Content Package Deployer Plugin, Date Parameter Plugin, Dynamic Extended, Choice Parameter Plugin, EasyQA Plugin, Embeddable Build Status Plugin, Filesystem List Parameter Plugin, Hidden Parameter Plugin, Image Tag Parameter Plugin, Jianliao Notification Plugin, JUnit Plugin, Maven Metadata Plugin for Jenkins CI server Plugin, Nested View Plugin, NS-ND Integration Performance Publisher Plugin, ontrack Jenkins Plugin, Package Version Plugin, Pipeline: Input Step Plugin, Readonly Parameter Plugin, Repository Connector Plugin, REST List Parameter Plugin, Sauce OnDemand Plugin, Squash TM Publisher (Squash4Jenkins) Plugin, Stash Branch Parameter Plugin, ThreadFix Plugin, vRealize Orchestrator Plugin, xUnit Plugin. Ein entfernter, anonymer oder authentisierter Angreifer kann diese Schwachstellen ausnutzen, um Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen und Daten zu manipulieren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion.
EPSS 17.55% · 95.2th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux | |
| Red Hat | Red Hat OpenShift Container Platform | |
| Red Hat | Red Hat OpenShift |
Exploit Intelligence
Timeline
- Jun 22, 2022 CVE Published
- Jun 23, 2022 EPSS Score
- Aug 11, 2022 EPSS Score
- Nov 14, 2022 EPSS Score
- Jan 1, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Aug 28, 2023 EPSS Score
- Oct 15, 2023 EPSS Score
- Jan 19, 2024 EPSS Score
- Mar 6, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2022/wid-sec-w-2022-0445.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2022-0445 advisory
- https://access.redhat.com/errata/RHSA-2023:0777 advisory
- https://access.redhat.com/errata/RHSA-2023:0697 advisory
- https://access.redhat.com/errata/RHSA-2023:0698 advisory
- https://access.redhat.com/errata/RHSA-2023:0017 advisory
- https://access.redhat.com/errata/RHSA-2022:9110 advisory
- https://access.redhat.com/errata/RHSA-2022:9111 advisory
- https://www.jenkins.io/security/advisory/2022-06-22/ advisory
- https://access.redhat.com/errata/RHSA-2022:6531 advisory