PT-2022-22046 · Jenkins · Jenkins Embeddable Build Status Plugin+1
Published
2022-06-22
·
Updated
2023-11-03
·
CVE-2022-34179
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Embeddable Build Status Plugin versions 2.0.3 and earlier
Description
The issue allows attackers without Overall/Read permission to specify paths to other SVG images on the Jenkins controller file system by exploiting a relative path traversal vulnerability. This is possible because the
style query parameter, used to choose a different SVG image style, does not restrict possible values.Recommendations
For Jenkins Embeddable Build Status Plugin versions 2.0.3 and earlier, update to version 2.0.4 or later, which restricts the
style query parameter to one of the three legal values.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Embeddable Build Status Plugin