Описание
Jenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files inside a user-specified directory as test results, allowing attackers able to control agent processes to obtain test results from files in an attacker-specified directory on the Jenkins controller.
Ссылки
- Mailing ListThird Party Advisory
- Vendor Advisory
- Mailing ListThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.28 (исключая)
cpe:2.3:a:jenkins:nunit:*:*:*:*:*:jenkins:*:*
EPSS
Процентиль: 76%
0.00962
Низкий
5.3 Medium
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-552
Связанные уязвимости
CVSS3: 5.3
github
больше 3 лет назад
Jenkins NUnit Plugin vulnerable to Protection Mechanism Failure
EPSS
Процентиль: 76%
0.00962
Низкий
5.3 Medium
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-552