jenkins-plugin/script-security: Whole-script approval in Script Security Plugin vulnerable to SHA-1 collisions
Published Nov 15, 2022
8.0
HIGHCVSS 3.1
EPSS 0.50%
Description
Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the script, making it vulnerable to collision attacks.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=1189.vb_a_b_7c8fd5fde
- Version 1175.1179.vea_f7532629e1StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Jenkins project | Jenkins Script Security Plugin | n/a |
|
- < 1190.v65867a_a_47126
No data.
Red Hat OpenShift Container Platform 4.10
jenkins-2-plugins-0:4.10.1675144701-1.el8
Fixed · RHSA-2023:0560
Red Hat OpenShift Container Platform 4.9
jenkins-2-plugins-0:4.9.1675668922-1.el8
Fixed · RHSA-2023:0777
OpenShift Developer Tools and Services
jenkins-2-plugins
Affected
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4.10 | jenkins-2-plugins-0:4.10.1675144701-1.el8 | Fixed | RHSA-2023:0560 |
| Red Hat OpenShift Container Platform 4.9 | jenkins-2-plugins-0:4.9.1675668922-1.el8 | Fixed | RHSA-2023:0777 |
| OpenShift Developer Tools and Services | jenkins-2-plugins | Affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
OpenShift 3.11 is already in the ELS support model phase. The Jenkins components are out of scope of the ELS support; hence OpenShift 3.11 Jenkins component is marked in this CVE as out of support scope.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
1 other source (GHSA) ▾
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.50% (0.00499) | 40.49th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.47% (0.00468) | 36.68th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.02% (0.00022) | 3.34th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.16% (0.00158) | 53.63th | v3 (v2023.03.01) |
| Jun 7, 2024 | 0.16% (0.00158) | 52.35th | v3 (v2023.03.01) |
| Apr 27, 2024 | 0.15% (0.00153) | 50.99th | v3 (v2023.03.01) |
| Dec 18, 2023 | 0.14% (0.00143) | 49.93th | v3 (v2023.03.01) |
| Nov 22, 2023 | 0.13% (0.00132) | 48.14th | v3 (v2023.03.01) |
| Oct 16, 2023 | 0.09% (0.00094) | 39.41th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.09% (0.00087) | 35.29th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Nov 16, 2022 | 0.89% (0.00885) | 26.85th | v2 (v2022.01.01) |
References (8)
- http://www.openwall.com/lists/oss-security/2022/11/15/4 mailing-listMailing List
- https://access.redhat.com/security/cve/CVE-2022-45379 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2143090 Issue Tracking
- https://github.com/advisories/GHSA-fv42-mx39-6fpw Advisory
- https://github.com/jenkinsci/script-security-plugin/commit/65867aa471265a16198b92fb439782ba3554da66
- https://nvd.nist.gov/vuln/detail/CVE-2022-45379
- https://www.cve.org/CVERecord?id=CVE-2022-45379
- https://www.jenkins.io/security/advisory/2022-11-15/#SECURITY-2564 Vendor Advisory
Change history (0)
No recorded changes yet.