Jenkins Report Info Plugin 1.2 and earlier does not perform path validation of the workspace directory while serving report files, allowing attackers with Item/Configure permission to retrieve Surefire failures, PMD violations, Findbugs bugs, and Checkstyle errors on the controller file system by editing the workspace path.

Project Subscriptions

Vendors Products
Jenkins Subscribe
Report Info Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-1584 Jenkins Report Info Plugin 1.2 and earlier does not perform path validation of the workspace directory while serving report files, allowing attackers with Item/Configure permission to retrieve Surefire failures, PMD violations, Findbugs bugs, and Checkstyle errors on the controller file system by editing the workspace path.
Github GHSA Github GHSA GHSA-cw5r-jx8r-9f7x Jenkins Report Info Plugin Path Traversal vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 10 Oct 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins report Info
CPEs cpe:2.3:a:jenkins:report_info:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins report Info

Thu, 07 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2025-02-13T17:54:07.582Z

Reserved: 2024-05-23T16:06:54.667Z

Link: CVE-2024-5273

cve-icon Vulnrichment

Updated: 2024-08-01T21:11:12.451Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-24T14:15:17.823

Modified: 2025-10-10T15:34:52.527

Link: CVE-2024-5273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses