CVE-2022-34204
Es existieren mehrere Schwachstellen in Jenkins Core und verschiedenen Plugins. Zu diesen Plugins gehören: Agent Server Parameter Plugin, Beaker builder Plugin, Convertigo Mobile Platform Plugin, CRX Content Package Deployer Plugin, Date Parameter Plugin, Dynamic Extended, Choice Parameter Plugin, EasyQA Plugin, Embeddable Build Status Plugin, Filesystem List Parameter Plugin, Hidden Parameter Plugin, Image Tag Parameter Plugin, Jianliao Notification Plugin, JUnit Plugin, Maven Metadata Plugin for Jenkins CI server Plugin, Nested View Plugin, NS-ND Integration Performance Publisher Plugin, ontrack Jenkins Plugin, Package Version Plugin, Pipeline: Input Step Plugin, Readonly Parameter Plugin, Repository Connector Plugin, REST List Parameter Plugin, Sauce OnDemand Plugin, Squash TM Publisher (Squash4Jenkins) Plugin, Stash Branch Parameter Plugin, ThreadFix Plugin, vRealize Orchestrator Plugin, xUnit Plugin. Ein entfernter, anonymer oder authentisierter Angreifer kann diese Schwachstellen ausnutzen, um Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen und Daten zu manipulieren. Die erfolgreiche Ausnutzung einiger dieser Schwachstellen erfordert eine Benutzerinteraktion.
EPSS 0.22% · 44.2th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform | |
| Red Hat | Red Hat OpenShift | |
| Red Hat | Red Hat Enterprise Linux |
Timeline
- Jun 22, 2022 CVE Published
- Jun 23, 2022 EPSS Score
- Jun 23, 2022 PoC Published
- Aug 11, 2022 EPSS Score
- Sep 27, 2022 EPSS Score
- Nov 14, 2022 EPSS Score
- Jan 1, 2023 EPSS Score
- Feb 18, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- May 24, 2023 EPSS Score
- Jul 11, 2023 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2022/wid-sec-w-2022-0445.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2022-0445 advisory
- https://access.redhat.com/errata/RHSA-2023:0777 advisory
- https://access.redhat.com/errata/RHSA-2023:0697 advisory
- https://access.redhat.com/errata/RHSA-2023:0698 advisory
- https://access.redhat.com/errata/RHSA-2023:0017 advisory
- https://access.redhat.com/errata/RHSA-2022:9110 advisory
- https://access.redhat.com/errata/RHSA-2022:9111 advisory
- https://www.jenkins.io/security/advisory/2022-06-22/ advisory
- https://access.redhat.com/errata/RHSA-2022:6531 advisory