Missing permission checks in Code Dx Plugin
CVE-2023-2196
4.3MEDIUM
What is CVE-2023-2196?
A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Item/Read permission to check for the existence of an attacker-specified file path on an agent file system.
Affected Version(s)
Jenkins Code Dx Plugin 0 <= 3.1.0