Описание
Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 798.v5cc688825312 (исключая)
cpe:2.3:a:jenkins:pipeline\:_groovy_libraries:*:*:*:*:*:*:*:*
EPSS
Процентиль: 21%
0.00289
Низкий
7.5 High
CVSS3
Дефекты
CWE-59
Связанные уязвимости
CVSS3: 5.5
redhat
2 месяца назад
Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.
CVSS3: 7.5
github
2 месяца назад
Jenkins Pipeline: Groovy Libraries Plugin does not prohibit symbolic links in shared libraries
EPSS
Процентиль: 21%
0.00289
Низкий
7.5 High
CVSS3
Дефекты
CWE-59