Description
Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with Item/Configure permission to determine whether a path on the Jenkins controller file system exists, without being able to access it.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0811 | Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with Item/Configure permission to determine whether a path on the Jenkins controller file system exists, without being able to access it. |
Github GHSA |
GHSA-478x-m3mx-7j3f | Jenkins HTML Publisher Plugin Path traversal vulnerability |
References
History
Tue, 06 May 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins html Publisher |
|
| CPEs | cpe:2.3:a:jenkins:html_publisher:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins html Publisher |
Thu, 31 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-02-13T17:47:18.996Z
Reserved: 2024-03-05T19:29:05.204Z
Link: CVE-2024-28151
Updated: 2024-08-02T00:48:49.387Z
Status : Analyzed
Published: 2024-03-06T17:15:10.570
Modified: 2025-05-06T20:45:17.777
Link: CVE-2024-28151
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA