Vulnerability GHSA-cgh7-rgqg-hrcx

Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 years ago
September 06, 2023 at 03:30 PM UTC
Path traversal allows exploiting XXE vulnerability in Jenkins Job Configuration History Plugin
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0

Summary

Path traversal allows exploiting XXE vulnerability in Jenkins Job Configuration History Plugin

Details

Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file called 'history.xml'.

Timeline

Published
3 years ago
September 06, 2023 at 03:30 PM UTC
Last Modified
2 years ago
February 16, 2024 at 08:13 AM UTC