PT-2022-18847 · Unknown+1 · Toad Edge Plugin+1

Daniel Beck

·

Published

2022-03-29

·

Updated

2023-11-17

·

CVE-2022-28148

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Continuous Integration with Toad Edge Plugin versions 2.3 and earlier
Description The file browser in Jenkins Continuous Integration with Toad Edge Plugin may interpret some paths to files as absolute on Windows, resulting in a path traversal issue. This allows attackers with Item/Read permission to obtain the contents of arbitrary files on Windows controllers.
Recommendations For versions 2.3 and earlier, update to a version that fixes this issue to prevent path traversal attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-28148
GHSA-MC92-C859-JR66

Affected Products

Jenkins
Toad Edge Plugin