Lucene search

K
osvGoogleOSV:GHSA-9JRH-HCH8-RR5C
HistoryMay 14, 2022 - 3:23 a.m.

Jenkins Copy To Slave Plugin allows access to arbitrary files on the Jenkins controller file system

2022-05-1403:23:41
Google
osv.dev
9

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.6%

An exposure of sensitive information vulnerability exists in Jenkins Copy To Slave Plugin version 1.4.4 and older in CopyToSlaveBuildWrapper.java that allows attackers with permission to configure jobs to read arbitrary files from the Jenkins master file system.

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.6%

Related for OSV:GHSA-9JRH-HCH8-RR5C