VYPR
High severity8.1NVD Advisory· Published Jan 12, 2022· Updated Jun 17, 2026

CVE-2022-23107

CVE-2022-23107

Description

Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the Jenkins controller file system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
io.jenkins.plugins:warnings-ngMaven
>= 9.8.0, < 9.10.39.10.3
io.jenkins.plugins:warnings-ngMaven
>= 9.6.0, < 9.7.19.7.1
io.jenkins.plugins:warnings-ngMaven
>= 9.1.0, < 9.5.29.5.2
io.jenkins.plugins:warnings-ngMaven
< 9.0.29.0.2

Affected products

2

Patches

Vulnerability mechanics

References

6

News mentions

1