6.5
CVSSv3

CVE-2024-23899

Published: 24/01/2024 Updated: 31/01/2024
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and previous versions does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file system.

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins git server

Mailing Lists

Jenkins is an open source automation server which enables developers around the world to reliably build, test, and deploy their software The following releases contain fixes for security vulnerabilities: * Jenkins 2442 * Jenkins LTS 24263 * Git server Plugin 99101v720e86326c09 * GitLab Branch Source Plugin 688v5fa_356ee8520 * Matrix Projec ...