GHSA-whgj-6m78-2gg9
GitHub Security Advisory
Arbitrary file read vulnerability in Jenkins AWS CodeCommit Trigger Plugin
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attackers with Item/Read permission to obtain the contents of arbitrary files on the Jenkins controller file system.
Affected Packages
Maven
org.jenkins-ci.plugins:aws-codecommit-trigger
Affected versions:
0
(last affected: 3.0.12)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 24, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.