GHSA-p5x5-jg3j-2jcj
Dashboard / Vulnerabilities / GHSA-p5x5-jg3j-2jcj
Summary: OS command injection in CryptoMove Plugin
Details: CryptoMove Plugin 0.1.33 and earlier allows the configuration of an OS command to execute as part of its build step configuration. This command will be executed on the Jenkins controller as the OS user account running Jenkins, allowing user with Job/Configure permission to execute an arbitrary OS command on the Jenkins controller.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2159, https://github.com/jenkinsci/cryptomove-plugin, https://jenkins.io/security/advisory/2020-03-09/#SECURITY-1635, http://www.openwall.com/lists/oss-security/2020/03/09/1
Affected packages
Package
Name: io.jenkins.plugins:cryptomove
Purl: pkg:maven/io.jenkins.plugins/cryptomove
Affected ranges
Type: ECOSYSTEM
Events:
