Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45846
HistoryMar 12, 2024 - 10:06 a.m.

Path Traversal

2024-03-1210:06:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
jenkins
html publisher plugin
path traversal
insufficient restrictions
follow_symlinks
htmlpublisher.java
symbolic links
item/configure permission
manipulate

AI Score

6.4

Confidence

High

EPSS

0

Percentile

9.0%

Jenkins HTML Publisher Plugin is vulnerable to Path Traversal. The vulnerability is caused due to insufficient restrictions on the FOLLOW_SYMLINKS variable within HtmlPublisher.java. The lack of finalization and the ability to change this variable via script during runtime allows attackers with Item/Configure permission to manipulate symbolic links, resulting in Path Traversal.

AI Score

6.4

Confidence

High

EPSS

0

Percentile

9.0%