Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 03 Oct 2025 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins filesystem List Parameter
CPEs cpe:2.3:a:jenkins:filesystem_list_parameter:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins filesystem List Parameter

Wed, 27 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Description Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-11-27T18:57:49.010Z

Reserved: 2024-11-26T08:57:17.660Z

Link: CVE-2024-54004

cve-icon Vulnrichment

Updated: 2024-11-27T18:55:43.637Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-27T17:15:15.443

Modified: 2025-10-03T00:53:14.090

Link: CVE-2024-54004

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.