GHSA-hgp9-2c4w-x9mh
Dashboard / Vulnerabilities / GHSA-hgp9-2c4w-x9mh
Summary: Jenkins Deployer Framework Plugin vulnerable to Path Traversal
Details: Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the name of files in methods implementing form validation. This allows attackers with Item/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system. Deployer Framework Plugin 86.v7b_a_4a_55b_f3ec ensures that only files contained inside the expected directory can be accessed.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-36890, https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2206, http://www.openwall.com/lists/oss-security/2022/07/27/1
Affected packages
Package
Name: org.jenkins-ci.plugins:deployer-framework
Purl: pkg:maven/org.jenkins-ci.plugins/deployer-framework
Affected ranges
Type: ECOSYSTEM
Events:
