First published: Thu Nov 21 2019(Updated: )
A path traversal vulnerability in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete arbitrary files on the Jenkins master.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Support Core | <=2.63 | |
maven/org.jenkins-ci.plugins:support-core | <=2.63 | 2.64 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16540 is treated as a critical vulnerability due to its potential to allow unauthorized file deletion on the Jenkins master.
To fix CVE-2019-16540, upgrade the Jenkins Support Core Plugin to version 2.64 or later.
Users of Jenkins Support Core Plugin versions 2.63 and earlier with Overall/Read permission are affected by CVE-2019-16540.
CVE-2019-16540 allows attackers to delete arbitrary files from the Jenkins master.
Jenkins Support Core Plugin versions up to and including 2.63 are vulnerable to CVE-2019-16540.