CVE-2022-23118: Improper Privilege Management
(updated )
Jenkins Debian Package Builder Plugin implements functionality that allows agents to invoke command-line git
at an attacker-specified path on the controller, allowing attackers able to control agent processes to invoke arbitrary OS commands on the controller.
References
Detect and mitigate CVE-2022-23118 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →