Path Traversal vulnerability in Jenkins Embeddable Build Status Plugin
Moderate severity
GitHub Reviewed
Published
Jun 24, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Package
Affected versions
< 2.0.4
Patched versions
2.0.4
Description
Published by the National Vulnerability Database
Jun 23, 2022
Published to the GitHub Advisory Database
Jun 24, 2022
Reviewed
Jul 5, 2022
Last updated
Jan 31, 2023
Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a
style
query parameter that is used to choose a different SVG image style without restricting possible values, resulting in a relative path traversal vulnerability that allows attackers without Overall/Read permission to specify paths to other SVG images on the Jenkins controller file system.Embeddable Build Status Plugin 2.0.4 restricts the
style
query parameter to one of the three legal values.References