Vulnerability GHSA-c7r5-cww9-64q6
Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 years ago
September 06, 2023 at 03:30 PM UTC
Path traversal in Jenkins Job Configuration History Plugin
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0
Summary
Path traversal in Jenkins Job Configuration History Plugin
Details
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict the 'name' query parameter when rendering a history entry, allowing attackers to have Jenkins render a manipulated configuration history that was not created by the plugin.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
3 months ago
Jenkins Job Configuration History Plugin doesn't redact encrypted values of secrets in job and agent configurations
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-8qr4-27mh-hqfr
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-8qr4-27mh-hqfr
Medium Risk
3 years ago
XSS vulnerability in Jenkins Job Configuration History Plugin
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-5jxp-f5rr-g6jc
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-5jxp-f5rr-g6jc
Medium Risk
3 years ago
Path traversal allows exploiting XXE vulnerability in Jenkins Job Configuration History Plugin
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-cgh7-rgqg-hrcx
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-cgh7-rgqg-hrcx
High Risk
3 years ago
Job Configuration History Plugin's path traversal allows exploiting XXE vulnerability
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-ghjw-fcf6-rpr9
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-ghjw-fcf6-rpr9
Medium Risk
4 years ago
Cross-site Scripting in Jenkins Job Configuration History Plugin
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-28w4-h56g-grg7
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-28w4-h56g-grg7
Impacted packages
Timeline
Published
3 years ago
September 06, 2023 at 03:30 PM UTC
Last Modified
2 years ago
February 16, 2024 at 08:16 AM UTC