[MAVEN:GHSA-VQ7J-6PCQ-F48P] Path traversal vulnerability in Blue Ocean Plugin

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag, blueocean.features.GIT_READ_SAVE_TYPE, that when set to the value clone allows an attacker with Item/Configure or Item/Create permission to read arbitrary files on the Jenkins controller file system.

Blue Ocean Plugin 1.23.3 no longer includes this feature and redirects existing usage to a safer alternative.

Package Affected Version
pkg:maven/io.jenkins.blueocean/blueocean <= 1.23.2
Package Fixed Version
pkg:maven/io.jenkins.blueocean/blueocean = 1.23.3
ID
MAVEN:GHSA-VQ7J-6PCQ-F48P
Severity
moderate
URL
https://github.com/advisories/GHSA-vq7j-6pcq-f48p
Published
2022-05-24T17:28:24
(2 years ago)
Modified
2023-12-14T10:14:51
(9 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.jenkins.blueocean/blueocean io.jenkins.blueocean blueocean <= 1.23.2
Fixed pkg:maven/io.jenkins.blueocean/blueocean io.jenkins.blueocean blueocean = 1.23.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...