PT-2022-15856 · Jenkins · Jenkins Publish Over Ssh Plugin+1
Justin Philip
+2
·
Published
2022-01-12
·
Updated
2023-11-30
·
CVE-2022-23113
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Publish Over SSH Plugin versions 1.22 and earlier
Description
The issue allows attackers with Item/Configure permission to discover the name of the Jenkins controller files due to a path traversal vulnerability. This occurs because the plugin performs a validation of the file name, specifying whether it is present or not.
Recommendations
For Jenkins Publish Over SSH Plugin versions 1.22 and earlier, update to a version later than 1.22 to resolve the issue. As a temporary workaround, consider restricting access to the plugin's file validation functionality to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Publish Over Ssh Plugin