Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vq7j-6pcq-f48p

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Path traversal vulnerability in Blue Ocean Plugin

Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag, blueocean.features.GIT_READ_SAVE_TYPE, that when set to the value clone allows an attacker with Item/Configure or Item/Create permission to read arbitrary files on the Jenkins controller file system.

Blue Ocean Plugin 1.23.3 no longer includes this feature and redirects existing usage to a safer alternative.

Пакеты

Наименование

io.jenkins.blueocean:blueocean

maven
Затронутые версииВерсия исправления

<= 1.23.2

1.23.3

EPSS

Процентиль: 85%
0.02419
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
redhat
больше 5 лет назад

Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/Create permission to read arbitrary files on the Jenkins controller file system.

CVSS3: 6.5
nvd
больше 5 лет назад

Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/Create permission to read arbitrary files on the Jenkins controller file system.

EPSS

Процентиль: 85%
0.02419
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22