PT-2022-4032 · Jenkins · Jenkins Clif Performance Testing Plugin+1

Brian Hysell

·

Published

2022-07-27

·

Updated

2023-11-22

·

CVE-2022-36894

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Jenkins CLIF Performance Testing Plugin versions 64.vc0d66de1dfb f and earlier
Description The issue is related to an arbitrary file write vulnerability. This vulnerability allows attackers with Overall/Read permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content. The vulnerability is due to incorrect restriction of a directory path with limited access.
Recommendations For Jenkins CLIF Performance Testing Plugin versions 64.vc0d66de1dfb f and earlier, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2022-04865
CVE-2022-36894
GHSA-6XF5-C3CX-67PV

Affected Products

Jenkins
Jenkins Clif Performance Testing Plugin