PT-2024-36011 · Jenkins · Jenkins Filesystem List Parameter Plugin+1

Daniel Beck

·

Published

2024-11-27

·

Updated

2025-10-03

·

CVE-2024-54004

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Jenkins Filesystem List Parameter Plugin versions 0.0.14 and earlier
Description: The issue allows attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system due to a lack of restriction on the path used for the File system objects list Parameter.
Recommendations: For Jenkins Filesystem List Parameter Plugin versions 0.0.14 and earlier, update to version 0.0.15 or later, which restricts paths used by the File system objects list Parameter to an allow list, with the default base directory set to $JENKINS HOME/userContent/. Additionally, consider configuring the allow list to include custom base directories as needed.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-54004
GHSA-FWXQ-3F52-5CMC

Affected Products

Jenkins
Jenkins Filesystem List Parameter Plugin