Описание
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file called 'history.xml'.
Ссылки
- Mailing ListThird Party Advisory
- Vendor Advisory
- Mailing ListThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1227.v7a_79fc4dc01f (включая)
cpe:2.3:a:jenkins:job_configuration_history:*:*:*:*:*:jenkins:*:*
EPSS
Процентиль: 21%
0.00066
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-611
Связанные уязвимости
CVSS3: 6.5
github
больше 2 лет назад
Path traversal allows exploiting XXE vulnerability in Jenkins Job Configuration History Plugin
EPSS
Процентиль: 21%
0.00066
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-611