Description
Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an agent.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4893 | Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an agent. |
Github GHSA |
GHSA-q58j-fhj7-j6fg | Path traversal vulnerability in Jenkins Subversion Plugin allows reading arbitrary files |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T18:23:27.475Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2021-21698
No data.
Status : Modified
Published: 2021-11-04T17:15:08.987
Modified: 2024-11-21T05:48:51.397
Link: CVE-2021-21698
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA