CVE-2023-24449

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-24449
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-24449.json
Aliases
Published
2023-01-26T21:18:18Z
Modified
2023-11-08T04:11:46.196550Z
Details

Jenkins PWauth Security Realm Plugin 0.4 and earlier does not restrict the names of files in methods implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

References

Affected packages

Git / github.com/jenkinsci/pwauth-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/pwauth-plugin
Events
Introduced
0The exact introduced commit is unknown
Last affected