Loading HuntDB...

GHSA-wr6p-j63r-xqhv

GitHub Security Advisory

Jenkins allows Data Insertion and Execution of Code by those with Read and HTTP Access

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.

Affected Packages

Maven org.jenkins-ci.main:jenkins-core
Affected versions: 0 (fixed in 1.466.2)
Maven org.jenkins-ci.main:jenkins-core
Affected versions: 1.467 (fixed in 1.482)

Related CVEs

Key Information

GHSA ID
GHSA-wr6p-j63r-xqhv
Published
April 23, 2022 12:40 AM
Last Modified
March 12, 2025 3:52 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.main:jenkins-core
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.