GHSA-h5mv-fv98-gqmq
Dashboard / Vulnerabilities / GHSA-h5mv-fv98-gqmq
Summary: OS command injection vulnerability in Jenkins Play Framework Plugin
Details: A form validation endpoint in Play Framework Plugin executes the `play` command to validate a given input file. Play Framework Plugin 1.0.2 and earlier lets users specify the path to the `play` command on the Jenkins controller. This results in an OS command injection vulnerability exploitable by users able to store such a file on the Jenkins controller (e.g. through archiving artifacts).
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2200, https://github.com/jenkinsci/play-plugin, https://jenkins.io/security/advisory/2020-06-03/#SECURITY-1879, http://www.openwall.com/lists/oss-security/2020/06/03/3
Affected packages
Package
Name: org.jenkins-ci.plugins:play-autotest-plugin
Purl: pkg:maven/org.jenkins-ci.plugins/play-autotest-plugin
Affected ranges
Type: ECOSYSTEM
Events:
