CVE-2022-30945: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
(updated )
Jenkins Pipeline: Groovy Plugin 2689.v434009a_31b_f1 and earlier allows loading any Groovy source files on the classpath of Jenkins and Jenkins plugins in sandboxed pipelines.
References
- www.openwall.com/lists/oss-security/2022/05/17/8
- github.com/advisories/GHSA-2xvx-rw9p-xgfc
- github.com/jenkinsci/workflow-cps-plugin/commit/76a7681702f42d65f77bbaa5463f146876ea62db
- github.com/jenkinsci/workflow-cps-plugin/commit/76b089ccd026b68012b0deb30c217395f7ca7dc2
- nvd.nist.gov/vuln/detail/CVE-2022-30945
- www.jenkins.io/security/advisory/2022-05-17/
Detect and mitigate CVE-2022-30945 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →