CVE-2022-28148: Path Traversal
The file browser in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Item/Read permission to obtain the contents of arbitrary files on Windows controllers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28148?
CVE-2022-28148 is considered a medium severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2022-28148?
To fix CVE-2022-28148, upgrade to Jenkins Continuous Integration with Toad Edge Plugin version 2.4 or later.
Who is affected by CVE-2022-28148?
Users of Jenkins Continuous Integration with Toad Edge Plugin versions 2.3 and earlier on Windows systems are affected by CVE-2022-28148.
What type of vulnerability is represented by CVE-2022-28148?
CVE-2022-28148 is a path traversal vulnerability that allows unauthorized access to arbitrary files on affected systems.
What permissions are required to exploit CVE-2022-28148?
An attacker needs Item/Read permission to exploit CVE-2022-28148 in Jenkins.