Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3395 | Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system. |
Github GHSA |
GHSA-fwxq-3f52-5cmc | Jenkins Filesystem List Parameter Plugin has Path Traversal vulnerability |
Fri, 03 Oct 2025 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins filesystem List Parameter |
|
| CPEs | cpe:2.3:a:jenkins:filesystem_list_parameter:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins filesystem List Parameter |
Wed, 27 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
cvssV3_1
|
Wed, 27 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-11-27T18:57:49.010Z
Reserved: 2024-11-26T08:57:17.660Z
Link: CVE-2024-54004
Updated: 2024-11-27T18:55:43.637Z
Status : Analyzed
Published: 2024-11-27T17:15:15.443
Modified: 2025-10-03T00:53:14.090
Link: CVE-2024-54004
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA