Path Traversal Vulnerability in Jenkins Publish Over SSH Plugin
CVE-2022-23113
4.3MEDIUM
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 12 January 2022
Summary
The Jenkins Publish Over SSH Plugin prior to version 1.23 is affected by a path traversal vulnerability. This issue occurs because the plugin inadequately validates file names, allowing attackers who possess Item/Configure permissions to exploit this flaw. By doing so, they can potentially discover the names of files on the Jenkins controller, leading to unauthorized access to sensitive information.
Affected Version(s)
Jenkins Publish Over SSH Plugin <= 1.22
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved