Логотип exploitDog
bind:CVE-2023-41932
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-41932

Количество 2

Количество 2

nvd логотип

CVE-2023-41932

больше 2 лет назад

Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file called 'history.xml'.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-cgh7-rgqg-hrcx

больше 2 лет назад

Path traversal allows exploiting XXE vulnerability in Jenkins Job Configuration History Plugin

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-41932

Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file called 'history.xml'.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-cgh7-rgqg-hrcx

Path traversal allows exploiting XXE vulnerability in Jenkins Job Configuration History Plugin

CVSS3: 6.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу