Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system.
This Cyber News was published on www.tenable.com. Publication date: Thu, 28 Nov 2024 13:11:03 +0000