CVE-2023-41930: Path Traversal
Published Sep 6, 2023
·Updated
Jenkins Job Configuration History Plugin 1227.v7a79fc4dc01f and earlier does not restrict the 'name' query parameter when rendering a history entry, allowing attackers to have Jenkins render a manipulated configuration history that was not created by the plugin.
Affected Software
2 affected componentsFixes available
jenkins Job Configuration History Jenkins<=1227.v7a_79fc4dc01f
maven/org.jenkins-ci.plugins:jobConfigHistory<=1227.v7a
1229.v3039470161a_d
Event History
Sep 6, 2023
CVE Published
12:08 PM
Data Sourced
12:08 PM
Description
Advisory Published
via GitHub·03:30 PM
Frequently Asked Questions
1
What is the vulnerability ID for the Jenkins Job Configuration History Plugin?
The vulnerability ID for the Jenkins Job Configuration History Plugin is CVE-2023-41930.
2
What is the name of the affected plugin?
The affected plugin is Jenkins Job Configuration History Plugin.
3
What is the severity of the vulnerability?
The severity of the vulnerability is medium.
4
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability by manipulating the 'name' query parameter when rendering a history entry.
5
Are there any known fixes or patches for this vulnerability?
Yes, there are fixes available for this vulnerability. Please refer to the provided references for more information.