Path traversal allows exploiting XXE vulnerability in Jenkins Job Configuration History Plugin
Moderate severity
GitHub Reviewed
Published
Sep 6, 2023
to the GitHub Advisory Database
•
Updated Jan 30, 2024
Package
Affected versions
<= 1227.v7a
Patched versions
1229.v3039470161a_d
Description
Published by the National Vulnerability Database
Sep 6, 2023
Published to the GitHub Advisory Database
Sep 6, 2023
Reviewed
Jan 30, 2024
Last updated
Jan 30, 2024
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file called 'history.xml'.
References