CVE-2023-40338: High severity Jenkins Folders Jenkins vulnerability
Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log file when attempting to access the Scan Organization Folder Log if no logs are available, exposing information about the Jenkins controller file system.
Other sources
Jenkins Folders Plugin displays an error message when attempting to access the Scan Organization Folder Log if no logs are available.
In Folders Plugin 6.846.v23698686f0f6 and earlier, this error message includes the absolute path of a log file, exposing information about the Jenkins controller file system.
Folders Plugin 6.848.ve3bfd7839a81 does not display the absolute path of a log file in the error message.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40338?
CVE-2023-40338 is a vulnerability in the Jenkins Folders Plugin that exposes the absolute path of a log file, potentially revealing sensitive information about the Jenkins controller file system.
What is the severity of CVE-2023-40338?
CVE-2023-40338 has a severity rating of 7.5 (High).
How does CVE-2023-40338 affect Jenkins Folders Plugin?
CVE-2023-40338 affects Jenkins Folders Plugin versions 6.846.v23698686f0f6 and earlier.
How can I fix CVE-2023-40338?
To fix CVE-2023-40338, update Jenkins Folders Plugin to version 6.848.ve3b or later.
Where can I find more information about CVE-2023-40338?
More information about CVE-2023-40338 can be found in the NVD vulnerability database and the Jenkins security advisory.