Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2m9w-9xh2-wxc3

Опубликовано: 16 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Link Following in Jenkins Pipeline Multibranch Plugin

Jenkins Pipeline: Multibranch Plugin prior to 2.23.1, 2.26.1, 696.698.v9b4218eea50f, and 707.v71c3f0a_6ccdb_ follows symbolic links to locations outside of the checkout directory for the configured SCM when reading files using the readTrusted step, allowing attackers able to configure Pipelines permission to read arbitrary files on the Jenkins controller file system.

Пакеты

Наименование

org.jenkins-ci.plugins.workflow:workflow-multibranch

maven
Затронутые версииВерсия исправления

>= 2.24, < 2.26.1

2.26.1

Наименование

org.jenkins-ci.plugins.workflow:workflow-multibranch

maven
Затронутые версииВерсия исправления

< 2.23.1

2.23.1

Наименование

org.jenkins-ci.plugins.workflow:workflow-multibranch

maven
Затронутые версииВерсия исправления

>= 696.v52535c46f4c9, < 696.698.v9b4218eea50f

696.698.v9b4218eea50f

Наименование

org.jenkins-ci.plugins.workflow:workflow-multibranch

maven
Затронутые версииВерсия исправления

>= 706.vd43c65dec013, < 707.v71c3f0a

707.v71c3f0a

EPSS

Процентиль: 84%
0.02131
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 6.5
redhat
почти 4 года назад

Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the checkout directory for the configured SCM when reading files using the readTrusted step, allowing attackers able to configure Pipelines permission to read arbitrary files on the Jenkins controller file system.

CVSS3: 6.5
nvd
почти 4 года назад

Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the checkout directory for the configured SCM when reading files using the readTrusted step, allowing attackers able to configure Pipelines permission to read arbitrary files on the Jenkins controller file system.

EPSS

Процентиль: 84%
0.02131
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-59