GHSA-5xpc-c4xv-7w62

Source
https://github.com/advisories/GHSA-5xpc-c4xv-7w62
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-5xpc-c4xv-7w62/GHSA-5xpc-c4xv-7w62.json
Aliases
Published
2023-01-26T21:30:18Z
Modified
2023-11-08T04:11:46.196550Z
Details

Jenkins PWauth Security Realm Plugin 0.4 and earlier does not restrict the names of files in methods implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

References

Affected packages

Maven / org.jvnet.hudson.plugins:pwauth

Package

Name
org.jvnet.hudson.plugins:pwauth

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Last affected
0.4

Affected versions

0.*

0.4