PT-2024-36011 · Jenkins · Jenkins Filesystem List Parameter Plugin+1
Daniel Beck
·
Published
2024-11-27
·
Updated
2025-10-03
·
CVE-2024-54004
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Jenkins Filesystem List Parameter Plugin versions 0.0.14 and earlier
Description:
The issue allows attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system due to a lack of restriction on the path used for the File system objects list Parameter.
Recommendations:
For Jenkins Filesystem List Parameter Plugin versions 0.0.14 and earlier, update to version 0.0.15 or later, which restricts paths used by the File system objects list Parameter to an allow list, with the default base directory set to $JENKINS HOME/userContent/. Additionally, consider configuring the allow list to include custom base directories as needed.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Filesystem List Parameter Plugin