PT-2023-24118 · Jenkins · Jenkins Sidebar Link Plugin+1

Atorralba

+1

·

Publicado

2023-05-16

·

Atualizado

2023-05-25

·

CVE-2023-32985

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Sidebar Link Plugin versions 2.2.1 and earlier
Description The issue allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system. This is due to the plugin not restricting the path of files in a method implementing form validation. The plugin allows specifying files in the userContent/ directory for use as link icons.
Recommendations For Jenkins Sidebar Link Plugin versions 2.2.1 and earlier, update to version 2.2.2 or later to ensure that only files located within the expected userContent/ directory can be accessed.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-32985
GHSA-PP8M-PRR7-WR8W

Produtos afetados

Jenkins
Jenkins Sidebar Link Plugin