Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system.
History

Wed, 27 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Description Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-11-27T18:57:49.010Z

Reserved: 2024-11-26T08:57:17.660Z

Link: CVE-2024-54004

cve-icon Vulnrichment

Updated: 2024-11-27T18:55:43.637Z

cve-icon NVD

Status : Received

Published: 2024-11-27T17:15:15.443

Modified: 2024-11-27T19:15:33.723

Link: CVE-2024-54004

cve-icon Redhat

No data.