CVE-2023-40338: High severity Jenkins Folders Jenkins vulnerability

Published Aug 16, 2023
·
Updated

Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log file when attempting to access the Scan Organization Folder Log if no logs are available, exposing information about the Jenkins controller file system.

Other sources

Jenkins Folders Plugin displays an error message when attempting to access the Scan Organization Folder Log if no logs are available.

In Folders Plugin 6.846.v23698686f0f6 and earlier, this error message includes the absolute path of a log file, exposing information about the Jenkins controller file system.

Folders Plugin 6.848.ve3bfd7839a81 does not display the absolute path of a log file in the error message.

Affected Software

3 affected componentsFixes available
maven/org.jenkins-ci.plugins:cloudbees-folder<6.848.ve3b
6.848.ve3b
redhat/Folders Plugin<6.848.
6.848.
Jenkins Folders Jenkins<=6.846.v23698686f0f6

Event History

Aug 16, 2023
CVE Published
02:32 PM
Data Sourced
02:32 PM
Description
Advisory Published
03:30 PM
Data Sourced
via Red Hat·07:49 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2023-40338?

CVE-2023-40338 is a vulnerability in the Jenkins Folders Plugin that exposes the absolute path of a log file, potentially revealing sensitive information about the Jenkins controller file system.

2

What is the severity of CVE-2023-40338?

CVE-2023-40338 has a severity rating of 7.5 (High).

3

How does CVE-2023-40338 affect Jenkins Folders Plugin?

CVE-2023-40338 affects Jenkins Folders Plugin versions 6.846.v23698686f0f6 and earlier.

4

How can I fix CVE-2023-40338?

To fix CVE-2023-40338, update Jenkins Folders Plugin to version 6.848.ve3b or later.

5

Where can I find more information about CVE-2023-40338?

More information about CVE-2023-40338 can be found in the NVD vulnerability database and the Jenkins security advisory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203