Jenkins Doktor Plugin 0.4.1 and earlier implements functionality that allows agent processes to render files on the controller as Markdown or Asciidoc, and error messages allow attackers able to control agent processes to determine whether a file with a given name exists.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published: 2022-02-15T16:11:39

Updated: 2024-08-03T04:36:06.439Z

Reserved: 2022-02-15T00:00:00

Link: CVE-2022-25204

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-02-15T17:15:11.047

Modified: 2023-11-03T16:23:24.437

Link: CVE-2022-25204

cve-icon Redhat

No data.