PT-2022-4037 · Jenkins · Jenkins Deployer Framework Plugin+1
Daniel Beck
·
Published
2022-07-27
·
Updated
2023-11-22
·
CVE-2022-36890
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Deployer Framework Plugin versions 85.v1d1888e8c021 and earlier
Description
The issue is related to incorrect restriction of the directory path name with limited access. Exploitation of this issue may allow a remote attacker to gain unauthorized access to protected information. Attackers with Item/Read permission can check for the existence of an attacker-specified file path on the Jenkins controller file system due to the lack of restriction on file names in methods implementing form validation.
Recommendations
For Jenkins Deployer Framework Plugin versions 85.v1d1888e8c021 and earlier, update to version 86.v7b a 4a 55b f3ec or later, which ensures that only files contained inside the expected directory can be accessed.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Deployer Framework Plugin