Bug 2055792 (CVE-2022-25179)
Summary: | CVE-2022-25179 workflow-multibranch: Pipeline-related plugins follow symbolic links or do not limit path names | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Pedro Sampaio <psampaio> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | abenaiss, aos-bugs, bmontgom, eparis, jburrell, jokerman, nstielau, pbhattac, spandura, sponnaga, vkumar |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: |
A flaw was found in Jenkins. The Pipeline: Multibranch follows symbolic links to locations outside of the checkout directory for the configured SCM when reading files using the readTrusted step. This flaw allows attackers that can configure Pipelines, to read arbitrary files on the Jenkins controller file system.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2022-03-29 11:01:58 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2058747, 2058748, 2058749, 2058750, 2058751, 2058752, 2063898, 2064010, 2069142, 2069143 | ||
Bug Blocks: | 2055807 |
Description
Pedro Sampaio
2022-02-17 16:20:22 UTC
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.10 Via RHSA-2022:1025 https://access.redhat.com/errata/RHSA-2022:1025 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.9 Via RHSA-2022:1021 https://access.redhat.com/errata/RHSA-2022:1021 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-25179 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.7 Via RHSA-2022:1248 https://access.redhat.com/errata/RHSA-2022:1248 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.11 Via RHSA-2022:1420 https://access.redhat.com/errata/RHSA-2022:1420 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.6 Via RHSA-2022:1620 https://access.redhat.com/errata/RHSA-2022:1620 |