CVE-2022-28146: Path Traversal
Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Item/Configure permission to read arbitrary files on the Jenkins controller by specifying an input folder on the Jenkins controller as a parameter to its build steps.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28146?
CVE-2022-28146 has a medium severity rating, allowing unauthorized file access on the Jenkins Controller.
How do I fix CVE-2022-28146?
To mitigate CVE-2022-28146, upgrade the Jenkins Continuous Integration with Toad Edge Plugin to version 2.4 or later.
What are the implications of CVE-2022-28146?
CVE-2022-28146 allows attackers with Item/Configure permission to read arbitrary files, potentially exposing sensitive data.
Which versions of the Jenkins Continuous Integration with Toad Edge Plugin are affected by CVE-2022-28146?
CVE-2022-28146 affects Jenkins Continuous Integration with Toad Edge Plugin versions 2.3 and earlier.
Can CVE-2022-28146 be exploited remotely?
CVE-2022-28146 can be exploited by attackers who have the necessary Item/Configure permissions on the Jenkins controller.