Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-1818 Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
Github GHSA Github GHSA GHSA-hcpw-v727-64qh Jenkins Team Concert Plugin does not perform permission checks in methods implementing form validation
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 11 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-12-11T16:57:20.721Z

Reserved: 2023-06-19T09:49:32.025Z

Link: CVE-2023-3315

cve-icon Vulnrichment

Updated: 2024-08-02T06:55:03.092Z

cve-icon NVD

Status : Modified

Published: 2023-06-19T21:15:42.177

Modified: 2024-12-11T17:15:13.593

Link: CVE-2023-3315

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-06-14T00:00:00Z

Links: CVE-2023-3315 - Bugzilla

cve-icon OpenCVE Enrichment

No data.