Improper access control in Pipeline: Shared Groovy Libraries - CVE-2022-29047
Published: April 13, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists todue the affected plugin does not apply to uses of the library step with a retriever argument pointing to a library in the current build’s repository and branch. A remote attacker can modify some Pipeline libraries.
Affected software
cri-o (Red Hat package)
jenkins-2-plugins (Red Hat package)
jenkins (Red Hat package)
Red Hat OpenShift Container Platform
How to mitigate CVE-2022-29047
cri-o (Red Hat package) - addressed in versions 1.20.7-4.rhaos4.7.gitb9df556.el7, 1.20.7-4.rhaos4.7.gitb9df556.el8, 1.22.3-5.rhaos4.9.git388405c.el8, 1.22.3-6.rhaos4.9.git388405c.el7
Red Hat OpenShift Container Platform - addressed in versions 4.7.52, 4.8.56, 4.9.33
jenkins-2-plugins (Red Hat package) - addressed in versions 4.7.1652967082-1.el8, 4.8.1672842762-1.el8, 4.9.1651754460-1.el8, 4.12.1675702407-1.el8
jenkins (Red Hat package) - addressed in versions 2.319.3.1651752848-1.el8, 2.361.1.1672840472-1.el8, 2.361.4.1675702346-3.el8
External References
Related Security Bulletins
- Improper access control in Jenkins Pipeline: Shared Groovy Libraries plugin
- Multiple vulnerabilities in OpenShift Container Platform 4.7
- Multiple vulnerabilities in OpenShift Container Platform 4.8
- OpenShift Developer Tools and Services for OCP 4.12 update for Jenkins and Jenkins-2-plugins
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.9 packages