CVE-2023-41932: XEE
Jenkins Job Configuration History Plugin 1227.v7a79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file called 'history.xml'.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Jenkins Job Configuration History Plugin vulnerability?
The vulnerability ID is CVE-2023-41932.
What is the severity of CVE-2023-41932?
The severity of CVE-2023-41932 is medium with a severity value of 6.5.
What does the Jenkins Job Configuration History Plugin vulnerability allow attackers to do?
The vulnerability allows attackers to delete attacker-specified directories on the Jenkins controller file system, as long as they contain a file called 'history.xml'.
What is the affected software version for CVE-2023-41932?
The affected software version is Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier.
Are there any references for this vulnerability?
Yes, you can find references for this vulnerability [here](http://www.openwall.com/lists/oss-security/2023/09/06/9) and [here](https://www.jenkins.io/security/advisory/2023-09-06/#SECURITY-3235).