Описание
Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which artifacts are published during the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure jobs to publish arbitrary files from the Jenkins controller file system to the previously configured CloudBees CD server.
Ссылки
- Mailing List
- Vendor Advisory
- Mailing List
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.32 (включая)
cpe:2.3:a:jenkins:cloudbees_cd:*:*:*:*:*:jenkins:*:*
EPSS
Процентиль: 43%
0.00205
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-59
Связанные уязвимости
CVSS3: 6.5
github
больше 2 лет назад
Jenkins CloudBees CD Plugin vulnerable to arbitrary file read
EPSS
Процентиль: 43%
0.00205
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-59