Improper Link Resolution Before File Access in Jenkins Pipeline: Groovy Plugin
Moderate severity
GitHub Reviewed
Published
Feb 16, 2022
to the GitHub Advisory Database
•
Updated May 30, 2023
Package
Affected versions
>= 2.93, < 2.94.1
< 2.92.1
>= 2.95, < 2648.2651.v230593e03e9f
Patched versions
2.94.1
2.92.1
2648.2651.v230593e03e9f
Description
Published by the National Vulnerability Database
Feb 15, 2022
Published to the GitHub Advisory Database
Feb 16, 2022
Reviewed
Jun 20, 2022
Last updated
May 30, 2023
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checkout directory for the configured SCM when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers able to configure Pipelines to read arbitrary files on the Jenkins controller file system.
References