Local Path Disclosure in Jenkins Git Plugin Affects Security & Data Privacy
CVE-2022-30947
What is CVE-2022-30947?
The Jenkins Git Plugin version 4.11.1 and earlier is susceptible to a local path disclosure vulnerability, where users with pipeline configuration permissions can access the file system of the Jenkins controller. This issue arises when attackers exploit the ability to check out Source Code Management (SCM) repositories using local paths as URLs, which could inadvertently expose limited information about other projects' SCM data. Organizations must review and secure pipeline configurations to mitigate potential data exposure and ensure robust security practices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Git Plugin <= 4.11.1
Jenkins Git Plugin 4.9.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved