Lucene search

K
osvGoogleOSV:GHSA-4PW5-R58H-FV24
HistoryMay 24, 2022 - 7:16 p.m.

Path traversal vulnerability on Windows in Jenkins

2022-05-2419:16:59
Google
osv.dev
5

0.001 Low

EPSS

Percentile

48.5%

The file browser for workspaces, archived artifacts, and userContent/ in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on Windows.

This results in a path traversal vulnerability allowing attackers with Overall/Read permission (Windows controller) or Job/Workspace permission (Windows agents) to obtain the contents of arbitrary files.\n\nThe file browser in Jenkins 2.315, LTS 2.303.2 refuses to serve files that would be considered absolute paths.

0.001 Low

EPSS

Percentile

48.5%

Related for OSV:GHSA-4PW5-R58H-FV24