PT-2022-15849 · Jenkins · Jenkins Warnings Next Generation Plugin+1

Kevin Guerroudj

·

Published

2022-01-12

·

Updated

2023-11-15

·

CVE-2022-23107

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Warnings Next Generation Plugin versions 9.10.2 and earlier
Description The issue allows attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the Jenkins controller file system due to the lack of restriction on the name of a file when configuring custom ID.
Recommendations For Jenkins Warnings Next Generation Plugin versions 9.10.2 and earlier, update to version 9.10.3 or later to resolve the issue.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-23107
GHSA-RVH4-G2RJ-HR9C

Affected Products

Jenkins
Jenkins Warnings Next Generation Plugin