Path traversal in Jenkins Job Configuration History Plugin
Moderate severity
GitHub Reviewed
Published
Sep 6, 2023
to the GitHub Advisory Database
•
Updated Jan 30, 2024
Package
Affected versions
<= 1227.v7a
Patched versions
1229.v3039470161a_d
Description
Published by the National Vulnerability Database
Sep 6, 2023
Published to the GitHub Advisory Database
Sep 6, 2023
Reviewed
Jan 30, 2024
Last updated
Jan 30, 2024
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict the 'name' query parameter when rendering a history entry, allowing attackers to have Jenkins render a manipulated configuration history that was not created by the plugin.
References