High severity8.1NVD Advisory· Published Nov 15, 2022· Updated Jun 17, 2026
CVE-2022-45381
CVE-2022-45381
Description
Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and bundles versions of Apache Commons Configuration library that enable the 'file:' prefix interpolator by default, allowing attackers able to configure Pipelines to read arbitrary files from the Jenkins controller file system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:pipeline-utility-stepsMaven | < 2.13.2 | 2.13.2 |
Affected products
3- cpe:2.3:a:jenkins:pipeline_utility_steps:*:*:*:*:*:jenkins:*:*Range: <2.13.2
- Range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-3g9q-cmgv-g4p6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-45381ghsaADVISORY
- www.jenkins.io/security/advisory/2022-11-15/nvdVendor AdvisoryWEB
- www.openwall.com/lists/oss-security/2022/11/15/4nvdMailing ListWEB
- github.com/jenkinsci/pipeline-utility-steps-plugin/commit/01be8ac0045027128fc1e9cf3a8b0709d08291eaghsaWEB
News mentions
1- Jenkins Security Advisory 2022-11-15Jenkins Security Advisories · Nov 15, 2022