Lucene search

K
nvd[email protected]NVD:CVE-2024-5273
HistoryMay 24, 2024 - 2:15 p.m.

CVE-2024-5273

2024-05-2414:15:17
web.nvd.nist.gov
4
jenkins
report info plugin
path validation
workspace directory
security vulnerability
surefire failures
pmd violations
findbugs bugs
checkstyle errors

AI Score

5.1

Confidence

High

EPSS

0

Percentile

9.0%

Jenkins Report Info Plugin 1.2 and earlier does not perform path validation of the workspace directory while serving report files, allowing attackers with Item/Configure permission to retrieve Surefire failures, PMD violations, Findbugs bugs, and Checkstyle errors on the controller file system by editing the workspace path.

AI Score

5.1

Confidence

High

EPSS

0

Percentile

9.0%