File Deletion Vulnerability in Jenkins Scriptler Plugin by Jenkins
CVE-2023-50764
8.1HIGH
What is CVE-2023-50764?
The Jenkins Scriptler Plugin prior to version 342.v6a_89fd40f466 lacks proper validation of the file name query parameter in an HTTP endpoint. This vulnerability can be exploited by users with Scriptler/Configure permission, enabling them to delete arbitrary files from the Jenkins controller's file system, potentially leading to critical data loss and disruption of service.
Affected Version(s)
Jenkins Scriptler Plugin 0 <= 342.v6a_89fd40f466