File Deletion Vulnerability in Jenkins Scriptler Plugin by Jenkins
CVE-2023-50764
8.1HIGH
Key Information:
- Vendor
Jenkins
- Status
- Vendor
- CVE Published:
- 13 December 2023
What is CVE-2023-50764?
The Jenkins Scriptler Plugin prior to version 342.v6a_89fd40f466 lacks proper validation of the file name query parameter in an HTTP endpoint. This vulnerability can be exploited by users with Scriptler/Configure permission, enabling them to delete arbitrary files from the Jenkins controller's file system, potentially leading to critical data loss and disruption of service.
Affected Version(s)
Jenkins Scriptler Plugin 0 <= 342.v6a_89fd40f466