[MAVEN:GHSA-V759-3FH9-84MX] Jenkins directory traversal vulnerability

Severity Moderate
Affected Packages 2
Fixed Packages 2
CVEs 1

Directory traversal vulnerability in the CLI job creation (hudson/cli/CreateJobCommand.java) in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to overwrite arbitrary files via the job name.

ID
MAVEN:GHSA-V759-3FH9-84MX
Severity
moderate
URL
https://github.com/advisories/GHSA-v759-3fh9-84mx
Published
2022-05-17T01:26:47
(2 years ago)
Modified
2024-03-05T14:38:44
(6 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.main/jenkins-core org.jenkins-ci.main jenkins-core < 1.532.2
Fixed pkg:maven/org.jenkins-ci.main/jenkins-core org.jenkins-ci.main jenkins-core = 1.532.2
Affected pkg:maven/org.jenkins-ci.main/jenkins-core org.jenkins-ci.main jenkins-core >= 1.533 < 1.551
Fixed pkg:maven/org.jenkins-ci.main/jenkins-core org.jenkins-ci.main jenkins-core = 1.551
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...