Логотип exploitDog
bind:CVE-2022-23107
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-23107

Количество 2

Количество 2

nvd логотип

CVE-2022-23107

около 4 лет назад

Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the Jenkins controller file system.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-rvh4-g2rj-hr9c

около 4 лет назад

Path Traversal in Jenkins Warnings Next Generation Plugin

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-23107

Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the Jenkins controller file system.

CVSS3: 8.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-rvh4-g2rj-hr9c

Path Traversal in Jenkins Warnings Next Generation Plugin

CVSS3: 8.1
2%
Низкий
около 4 лет назад

Уязвимостей на страницу