Описание
Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file system.
A flaw was found in the Git Server Plugin for Jenkins. This issue could allow an attacker to read the first two lines of arbitrary files on the server's file system.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins | Will not fix | ||
OCP-Tools-4.12-RHEL-8 | jenkins | Fixed | RHSA-2024:3635 | 05.06.2024 |
OCP-Tools-4.12-RHEL-8 | jenkins-2-plugins | Fixed | RHSA-2024:3635 | 05.06.2024 |
OCP-Tools-4.13-RHEL-8 | jenkins | Fixed | RHSA-2024:3636 | 05.06.2024 |
OCP-Tools-4.13-RHEL-8 | jenkins-2-plugins | Fixed | RHSA-2024:3636 | 05.06.2024 |
OCP-Tools-4.14-RHEL-8 | jenkins | Fixed | RHSA-2024:3634 | 05.06.2024 |
OCP-Tools-4.14-RHEL-8 | jenkins-2-plugins | Fixed | RHSA-2024:3634 | 05.06.2024 |
OCP-Tools-4.15-RHEL-8 | jenkins | Fixed | RHSA-2024:4597 | 17.07.2024 |
OCP-Tools-4.15-RHEL-8 | jenkins-2-plugins | Fixed | RHSA-2024:4597 | 17.07.2024 |
Показывать по
Дополнительная информация
Статус:
8.8 High
CVSS3
Связанные уязвимости
Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file system.
Arbitrary file read vulnerability in Git server Plugin can lead to RCE
Уязвимость библиотеки args4j плагина Jenkins Git server Plugin, позволяющая нарушителю читать первые две строки произвольных файлов
8.8 High
CVSS3