Medium severity4.3NVD Advisory· Published Feb 15, 2022· Updated Jun 17, 2026
CVE-2022-25188
CVE-2022-25188
Description
Jenkins Fortify Plugin 20.2.34 and earlier does not sanitize the appName and appVersion parameters of its Pipeline steps, allowing attackers with Item/Configure permission to write or overwrite .xml files on the Jenkins controller file system with content not controllable by the attacker.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:fortifyMaven | < 20.2.35 | 20.2.35 |
Affected products
3- Range: unspecified
Patches
Vulnerability mechanics
References
5- www.jenkins.io/security/advisory/2022-02-15/nvdIssue TrackingPatchVendor AdvisoryWEB
- www.openwall.com/lists/oss-security/2022/02/15/2nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-23h5-8ph6-7rfcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25188ghsaADVISORY
- github.com/jenkinsci/fortify-plugin/commit/ba3030cb63bb86b6bb13342664e0e319f2fee374ghsaWEB
News mentions
1- Jenkins Security Advisory 2022-02-15Jenkins Security Advisories · Feb 15, 2022