Loading HuntDB...

GHSA-j5qq-6rpm-qjgh

GitHub Security Advisory

Jenkins Deployer Framework Plugin does not restrict application path of applications when configuring a deployment

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller file system to the selected service.

Affected Packages

Maven org.jenkins-ci.plugins:deployer-framework
Affected versions: 0 (fixed in 86.v7b_a_4a_55b_f3ec)

Related CVEs

Key Information

GHSA ID
GHSA-j5qq-6rpm-qjgh
Published
July 28, 2022 12:00 AM
Last Modified
December 9, 2022 8:54 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:deployer-framework
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 5, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.