← Vulnerability feed

Vulnerability record · CVE-2022-25183 · published 15 February 2022

CVE-2022-25183: Jenkins pipeline\ vulnerability

Jenkins · Pipeline\

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories without any sanitization, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM using specially crafted library names if a global Pipeline library configured to use caching already exists.

8.8 CVSS 3.1 High EPSS 1.6% · top 25.6%
8.8CVSS 3.1 base score, v2 6.5
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories without any sanitization, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM using specially crafted library names if a global Pipeline library configured to use caching already exists.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-25183 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2019-1003030Jenkins Pipeline Groovy Plugin sandbox bypass allows arbitrary code executionThe Jenkins Pipeline: Groovy Plugin (2.63 and earlier) contains a sandbox bypass in CpsGroovyShell.java. Attackers who can control pipeline scripts c…KEVEPSS 97%analysed9.9CVE-2022-43402Jenkins pipeline\ vulnerabilityA sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pipeline: Groovy Plugin 2802.v5…EPSS 1.3%9.8CVE-2019-1003041Jenkins pipeline\ vulnerabilityA sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scr…EPSS 3.4%8.8CVE-2022-43407Jenkins pipeline\ cross-site request forgery vulnerabilityJenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specified ID of the 'input' step, wh…EPSS 0.53%8.8CVE-2022-25181Jenkins pipeline\ vulnerabilityA sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure…EPSS 1.6%8.8CVE-2022-25182Jenkins pipeline\ vulnerabilityA sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure…EPSS 1.6%8.8CVE-2022-25173Jenkins pipeline\ os command injection vulnerabilityJenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typ…EPSS 1.4%8.8CVE-2022-25174Jenkins pipeline\ os command injection vulnerabilityJenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libr…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2022-25183), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.