Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrary files in the Jenkins servlet resources via directory traversal sequences in a request to jnlpJars/.
References
Configurations
History
No history.
Information
Published : 2015-11-25 20:59
Updated : 2024-02-28 15:21
NVD link : CVE-2015-5322
Mitre link : CVE-2015-5322
CVE.ORG link : CVE-2015-5322
JSON object : View
Products Affected
jenkins
- jenkins
redhat
- openshift
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')