Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag, blueocean.features.GIT_READ_SAVE_TYPE, that when set to the value clone allows an attacker with Item/Configure or Item/Create permission to read arbitrary files on the Jenkins controller file system.
Blue Ocean Plugin 1.23.3 no longer includes this feature and redirects existing usage to a safer alternative.
{
"nvd_published_at": "2020-09-16T14:15:00Z",
"severity": "MODERATE",
"github_reviewed_at": "2022-12-29T01:30:01Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-22"
]
}