Vulnerabilities > Jenkins > Docker Commons > High

DATE CVE VULNERABILITY TITLE RISK
2022-01-12 CVE-2022-20617 OS Command Injection vulnerability in Jenkins Docker Commons
Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM repository.
network
low complexity
jenkins CWE-78
8.8