Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m935-chfp-9f63

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Arbitrary file write vulnerability in Jenkins Cobertura Plugin

An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system. Cobertura Plugin 1.16 sanitizes the file paths to prevent escape from the base directory.

Пакеты

Наименование

org.jenkins-ci.plugins:cobertura

maven
Затронутые версииВерсия исправления

<= 1.15

1.16

EPSS

Процентиль: 90%
0.05232
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
redhat
почти 6 лет назад

An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system.

CVSS3: 6.5
nvd
почти 6 лет назад

An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system.

EPSS

Процентиль: 90%
0.05232
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22