← Vulnerability feed

Vulnerability record · CVE-2022-25173 · published 15 February 2022

CVE-2022-25173: Jenkins pipeline\ os command injection vulnerability

Jenkins · Pipeline\

Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

8.8 CVSS 3.1 High EPSS 1.4% · top 27.8% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 6.5
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-25173 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2019-1003030Jenkins Pipeline Groovy Plugin sandbox bypass allows arbitrary code executionThe Jenkins Pipeline: Groovy Plugin (2.63 and earlier) contains a sandbox bypass in CpsGroovyShell.java. Attackers who can control pipeline scripts c…KEVEPSS 97%analysed9.9CVE-2022-43402Jenkins pipeline\ vulnerabilityA sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pipeline: Groovy Plugin 2802.v5…EPSS 1.3%9.8CVE-2019-1003041Jenkins pipeline\ vulnerabilityA sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scr…EPSS 3.4%8.8CVE-2022-43407Jenkins pipeline\ cross-site request forgery vulnerabilityJenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specified ID of the 'input' step, wh…EPSS 0.53%8.8CVE-2022-25181Jenkins pipeline\ vulnerabilityA sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure…EPSS 1.6%8.8CVE-2022-25182Jenkins pipeline\ vulnerabilityA sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure…EPSS 1.6%8.8CVE-2022-25183Jenkins pipeline\ vulnerabilityJenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories witho…EPSS 1.6%8.8CVE-2022-25174Jenkins pipeline\ os command injection vulnerabilityJenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libr…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2022-25173), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.