PT-2022-4037 · Jenkins · Jenkins Deployer Framework Plugin+1

Daniel Beck

·

Published

2022-07-27

·

Updated

2023-11-22

·

CVE-2022-36890

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Deployer Framework Plugin versions 85.v1d1888e8c021 and earlier
Description The issue is related to incorrect restriction of the directory path name with limited access. Exploitation of this issue may allow a remote attacker to gain unauthorized access to protected information. Attackers with Item/Read permission can check for the existence of an attacker-specified file path on the Jenkins controller file system due to the lack of restriction on file names in methods implementing form validation.
Recommendations For Jenkins Deployer Framework Plugin versions 85.v1d1888e8c021 and earlier, update to version 86.v7b a 4a 55b f3ec or later, which ensures that only files contained inside the expected directory can be accessed.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04870
CVE-2022-36890
GHSA-HGP9-2C4W-X9MH

Affected Products

Jenkins
Jenkins Deployer Framework Plugin