GHSA-j5qq-6rpm-qjgh
GitHub Security Advisory
Jenkins Deployer Framework Plugin does not restrict application path of applications when configuring a deployment
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller file system to the selected service.
Affected Packages
Maven
org.jenkins-ci.plugins:deployer-framework
Affected versions:
0
(fixed in 86.v7b_a_4a_55b_f3ec)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 5, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.