Description
A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qr42-82qj-mw65 | Improper Limitation of a Pathname to a Restricted Directory in Jenkins |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-04T22:17:20.356Z
Reserved: 2019-03-29T00:00:00.000Z
Link: CVE-2019-10352
No data.
Status : Modified
Published: 2019-07-17T16:15:12.413
Modified: 2024-11-21T04:18:57.060
Link: CVE-2019-10352
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA