← volver
CVE-2022-25183

CVE-2022-25183

EPSS 1.5%
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS EPSS 1.5%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
15 feb 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories without any sanitization, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM using specially crafted library names if a global Pipeline library configured to use caching already exists.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →