PT-2024-2758 · Jenkins+1 · Jenkins Log Command Plugin+2
Published
2024-01-24
·
Updated
2024-04-11
·
CVE-2024-23904
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Log Command Plugin versions 1.0.2 and earlier
Description
The issue is related to the command parser feature in the Jenkins Log Command Plugin, which replaces an '@' character followed by a file path in an argument with the file's contents. This allows unauthenticated attackers to read content from arbitrary files on the Jenkins controller file system. The exploitation of this issue may enable a remote attacker to read contents from arbitrary files.
Recommendations
For Jenkins Log Command Plugin versions 1.0.2 and earlier, consider disabling the command parser feature that replaces the '@' character with file contents until a patch is available. Restrict access to sensitive files on the Jenkins controller file system to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Log Command Plugin
Red Os