GHSA-p5x5-jg3j-2jcj
GitHub Security Advisory
OS command injection in CryptoMove Plugin
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
CryptoMove Plugin 0.1.33 and earlier allows the configuration of an OS command to execute as part of its build step configuration. This command will be executed on the Jenkins controller as the OS user account running Jenkins, allowing user with Job/Configure permission to execute an arbitrary OS command on the Jenkins controller.
Affected Packages
Maven
io.jenkins.plugins:cryptomove
Affected versions:
0
(last affected: 0.1.33)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 27, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.