Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-89vc-7frq-2rfj

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Jenkins has Local File Inclusion Vulnerability

Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrary files in the Jenkins servlet resources via directory traversal sequences in a request to jnlpJars/.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 1.626, < 1.638

1.638

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 1.625.2

1.625.2

EPSS

Процентиль: 38%
0.00169
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-22

Связанные уязвимости

ubuntu
около 10 лет назад

Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrary files in the Jenkins servlet resources via directory traversal sequences in a request to jnlpJars/.

redhat
около 10 лет назад

Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrary files in the Jenkins servlet resources via directory traversal sequences in a request to jnlpJars/.

nvd
около 10 лет назад

Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrary files in the Jenkins servlet resources via directory traversal sequences in a request to jnlpJars/.

debian
около 10 лет назад

Directory traversal vulnerability in Jenkins before 1.638 and LTS befo ...

EPSS

Процентиль: 38%
0.00169
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-22