GHSA-24jc-w55j-5p83

Suggest an improvement
Source
https://github.com/advisories/GHSA-24jc-w55j-5p83
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-24jc-w55j-5p83/GHSA-24jc-w55j-5p83.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-24jc-w55j-5p83
Aliases
Published
2022-05-13T01:30:58Z
Modified
2025-03-13T18:20:21Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Jenkins TAP Plugin allows Path Traversal
Details

Directory traversal vulnerability in the TAP plugin before 1.25 in Jenkins allows remote attackers to read arbitrary files via an unspecified parameter.

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-03-13T17:58:40Z",
    "nvd_published_at":  "2017-02-09T15:59:00Z",
    "severity":  "HIGH"
}
References

Affected packages

Maven / org.tap4j:tap

Package

Name
org.tap4j:tap
View open source insights on deps.dev
Purl
pkg:maven/org.tap4j/tap

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.25

Affected versions

1.*
1.0
1.1
1.2
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.3
1.5
1.6
1.7
1.8
1.9
1.10
1.11
1.12
1.13
1.14
1.15
1.16
1.17
1.18-alpha
1.18
1.18-1-alpha
1.20
1.22
1.23
1.24

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-24jc-w55j-5p83/GHSA-24jc-w55j-5p83.json"