From dc5f5ac679faf50e48d2b0018798f2f9e49d812e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 27 Oct 2023 19:06:30 +0000 Subject: [PATCH] Publish GHSA-pfwp-q984-w7wh --- .../2022/02/GHSA-pfwp-q984-w7wh/GHSA-pfwp-q984-w7wh.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2022/02/GHSA-pfwp-q984-w7wh/GHSA-pfwp-q984-w7wh.json b/advisories/github-reviewed/2022/02/GHSA-pfwp-q984-w7wh/GHSA-pfwp-q984-w7wh.json index 1352ad24ae5..34a9ce10b1b 100644 --- a/advisories/github-reviewed/2022/02/GHSA-pfwp-q984-w7wh/GHSA-pfwp-q984-w7wh.json +++ b/advisories/github-reviewed/2022/02/GHSA-pfwp-q984-w7wh/GHSA-pfwp-q984-w7wh.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-pfwp-q984-w7wh", - "modified": "2022-06-20T22:36:46Z", + "modified": "2023-10-27T19:04:37Z", "published": "2022-02-16T00:01:31Z", "aliases": [ "CVE-2022-25183" ], - "summary": "Protection Mechanism Failure in Jenkins Pipeline: Shared Groovy Libraries Plugin", - "details": "Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories without any sanitization, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM using specially crafted library names if a global Pipeline library configured to use caching already exists.", + "summary": "Jenkins Pipeline: Deprecated Groovy Libraries Plugin Protection Mechanism Failure", + "details": "Jenkins Pipeline: Deprecated Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories without any sanitization.\n\nThis allows attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM using specially crafted library names if a global Pipeline library configured to use caching already exists.\n\nPipeline: Deprecated Groovy Libraries Plugin 561.va_ce0de3c2d69 sanitizes the names of Pipeline libraries when creating library cache directories.", "severity": [ { "type": "CVSS_V3",