GHSA-8qh4-fghr-6fxg
GitHub Security Advisory
Improper Limitation of a Pathname to a Restricted Directory in Jenkins Google OAuth Credentials Plugin
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credentials in Jenkins to obtain the contents of any file on the Jenkins master.
Affected Packages
Maven
org.jenkins-ci.plugins:google-oauth-plugin
Affected versions:
0
(fixed in 0.10)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.