VYPR
High severity8.8NVD Advisory· Published Feb 15, 2022· Updated Jun 17, 2026

CVE-2022-25175

CVE-2022-25175

Description

Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins.workflow:workflow-multibranchMaven
< 707.v71c3f0a_6ccdb707.v71c3f0a_6ccdb

Affected products

3

Patches

Vulnerability mechanics

References

4

News mentions

1