Описание
Jenkins 2.318 and earlier, LTS 2.303.2 and earlier allows any agent to read and write the contents of any build directory stored in Jenkins with very few restrictions.
Ссылки
- Mailing ListThird Party Advisory
- PatchVendor Advisory
- Mailing ListThird Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
Связанные уязвимости
Jenkins 2.318 and earlier, LTS 2.303.2 and earlier allows any agent to read and write the contents of any build directory stored in Jenkins with very few restrictions.
Jenkins 2.318 and earlier, LTS 2.303.2 and earlier allows any agent to ...
Agent-to-controller access control allows reading/writing most content of build directories in Jenkins
Уязвимость сервера автоматизации Jenkins, связанная с использованием неполного чёрного списка, позволяющая нарушителю читать и записывать содержимое любого каталога сборки
EPSS
9.1 Critical
CVSS3
6.4 Medium
CVSS2