CVE-2022-27208: Path Traversal
Published Mar 15, 2022
·Updated
Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read arbitrary files on the Jenkins controller.
Affected Software
1 affected component
Jenkins Kubernetes Continuous Deploy Jenkins<=2.3.1
Event History
Mar 15, 2022
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-27208?
CVE-2022-27208 has been rated as a high severity vulnerability due to its potential impact on unauthorized file access.
2
Who is affected by CVE-2022-27208?
CVE-2022-27208 affects users of Jenkins Kubernetes Continuous Deploy Plugin versions 2.3.1 and earlier.
3
What can attackers do with CVE-2022-27208?
Attackers with the Credentials/Create permission can read arbitrary files from the Jenkins controller due to CVE-2022-27208.
4
How do I fix CVE-2022-27208?
To fix CVE-2022-27208, upgrade the Jenkins Kubernetes Continuous Deploy Plugin to version 2.3.2 or later.
5
What permissions are required to exploit CVE-2022-27208?
Exploitation of CVE-2022-27208 requires the attacker to have Credentials/Create permissions in Jenkins.