Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an agent.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | freebsd-upgrade-package-jenkinsfreebsd-upgrade-package-jenkins-lts | Nov 4, 2022 | Nov 4, 2021 | |
| Jenkins 2021 11 04 | jenkins-lts-upgrade-2_303_3jenkins-upgrade-2_319 | Dec 2, 2021 | Nov 4, 2021 | |
| Redhat Openshift | linuxrpm-upgrade-jenkins-2-plugins | Nov 30, 2021 | Nov 4, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub