Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93mx-2vf9-28c4

Опубликовано: 24 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Path Traversal vulnerability in Jenkins Embeddable Build Status Plugin

Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a style query parameter that is used to choose a different SVG image style without restricting possible values, resulting in a relative path traversal vulnerability that allows attackers without Overall/Read permission to specify paths to other SVG images on the Jenkins controller file system.

Embeddable Build Status Plugin 2.0.4 restricts the style query parameter to one of the three legal values.

Пакеты

Наименование

org.jenkins-ci.plugins:embeddable-build-status

maven
Затронутые версииВерсия исправления

< 2.0.4

2.0.4

EPSS

Процентиль: 53%
0.00307
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to choose a different SVG image style without restricting possible values, resulting in a relative path traversal vulnerability that allows attackers without Overall/Read permission to specify paths to other SVG images on the Jenkins controller file system.

EPSS

Процентиль: 53%
0.00307
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22