Lucene search

K
osvGoogleOSV:GHSA-VQ7J-6PCQ-F48P
HistoryMay 24, 2022 - 5:28 p.m.

Path traversal vulnerability in Blue Ocean Plugin

2022-05-2417:28:24
Google
osv.dev
12
blue ocean plugin
path traversal vulnerability
undocumented feature
jenkins controller file system

EPSS

0.001

Percentile

48.5%

Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag, blueocean.features.GIT_READ_SAVE_TYPE, that when set to the value clone allows an attacker with Item/Configure or Item/Create permission to read arbitrary files on the Jenkins controller file system.

Blue Ocean Plugin 1.23.3 no longer includes this feature and redirects existing usage to a safer alternative.

EPSS

0.001

Percentile

48.5%