Medium severity6.5NVD Advisory· Published Feb 15, 2022· Updated Jun 17, 2026
CVE-2022-25179
CVE-2022-25179
Description
Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the checkout directory for the configured SCM when reading files using the readTrusted step, allowing attackers able to configure Pipelines permission to read arbitrary files on the Jenkins controller file system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins.workflow:workflow-multibranchMaven | >= 2.24, < 2.26.1 | 2.26.1 |
org.jenkins-ci.plugins.workflow:workflow-multibranchMaven | < 2.23.1 | 2.23.1 |
org.jenkins-ci.plugins.workflow:workflow-multibranchMaven | >= 696.v52535c46f4c9, < 696.698.v9b4218eea50f | 696.698.v9b4218eea50f |
org.jenkins-ci.plugins.workflow:workflow-multibranchMaven | >= 706.vd43c65dec013, < 707.v71c3f0a | 707.v71c3f0a |
Affected products
3- cpe:2.3:a:jenkins:pipeline\:_multibranch:*:*:*:*:*:jenkins:*:*Range: <=706.vd43c65dec013
- Jenkins project/Jenkins Pipeline: Multibranch Pluginv5Range: unspecified
Patches
Vulnerability mechanics
References
4News mentions
1- Jenkins Security Advisory 2022-02-15Jenkins Security Advisories · Feb 15, 2022