CVE-2019-10352
CVSS v3.0
6.5 (Medium)
CVSS v2.0
4 (Medium)
EPSS
55.89 % (98th)
Affected Products
1
Advisories
3
A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build.
Weaknesses
- CWE-22
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CVE Status
- PUBLISHED
- CNA
- Jenkins Project
- Published Date
-
2019-07-17 16:15:12
(5 years ago) - Updated Date
-
2023-10-25 18:16:17
(10 months ago)
Affected Products
Loading...
Loading...
Loading...
Configuration #1
|
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...