Path Traversal Vulnerability in Jenkins Publish Over SSH Plugin
CVE-2022-23113

4.3MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
12 January 2022

Summary

The Jenkins Publish Over SSH Plugin prior to version 1.23 is affected by a path traversal vulnerability. This issue occurs because the plugin inadequately validates file names, allowing attackers who possess Item/Configure permissions to exploit this flaw. By doing so, they can potentially discover the names of files on the Jenkins controller, leading to unauthorized access to sensitive information.

Affected Version(s)

Jenkins Publish Over SSH Plugin <= 1.22

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.