Aller au contenu

Fiche vulnérabilité

CVE-2022-34181 : faille critique jenkins xunit (CVSS 9.1)

Description

Jenkins xUnit Plugin 3.0.8 and earlier implements an agent-to-controller message that creates a user-specified directory if it doesn't exist, and parsing files inside it as test results, allowing attackers able to control agent processes to create an arbitrary directory on the Jenkins controller or to obtain test results from existing files in an attacker-specified directory.

En bref

Sévérité
Critique (CVSS 9.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
23 juin 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • jenkins xunit

Références

Rechercher une autre vulnérabilité dans la base CVE