Beveiligingsadvies

CVE-2026-57282

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-24 13:20:05
Laatst bijgewerkt 2026-06-24 14:00:22
Toegewezen door jenkins
CVSS-score 5.0
Status PUBLISHED

Beschrijving

Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able to control the name of a build's working directory to execute arbitrary operating system commands on the agent.