Loading HuntDB...

CVE-2023-41932

UNKNOWN
Published 2023-09-06T12:08:53.687Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2023-41932. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file called 'history.xml'.

Available Exploits

No exploits available for this CVE.

Related News

No news articles found for this CVE.

Affected Products

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

✓ GitHub Reviewed MODERATE

Path traversal allows exploiting XXE vulnerability in Jenkins Job Configuration History Plugin

GHSA-cgh7-rgqg-hrcx

Advisory Details

Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file called 'history.xml'.

Affected Packages

Maven org.jenkins-ci.plugins:jobConfigHistory
ECOSYSTEM: ≥0 <1229.v3039470161a_d

CVSS Scoring

CVSS Score

5.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Advisory provided by GitHub Security Advisory Database. Published: September 6, 2023, Modified: January 30, 2024

References

Published: 2023-09-06T12:08:53.687Z
Last Modified: 2024-09-26T19:58:14.787Z
Copied to clipboard!