CVE-2024-28151: Path Traversal
Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with Item/Configure permission to determine whether a path on the Jenkins controller file system exists, without being able to access it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28151?
CVE-2024-28151 is considered a medium severity vulnerability due to the potential for path disclosure on the Jenkins controller.
How do I fix CVE-2024-28151?
To fix CVE-2024-28151, update the Jenkins HTML Publisher Plugin to version 1.32.1 or later.
What type of permissions are required to exploit CVE-2024-28151?
Exploitation of CVE-2024-28151 requires Item/Configure permissions on the Jenkins instance.
Can CVE-2024-28151 lead to unauthorized access?
CVE-2024-28151 does not directly allow unauthorized access but can reveal file paths on the Jenkins controller.
Which versions of Jenkins HTML Publisher Plugin are affected by CVE-2024-28151?
CVE-2024-28151 affects versions 1.32 and earlier of the Jenkins HTML Publisher Plugin.