CVE Database
/

CVE-2022-34179

Back to search

CVE-2022-34179

Published: Jun 22, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to choose a different SVG image style without restricting possible values, resulting in a relative path traversal vulnerability that allows attackers without Overall/Read permission to specify paths to other SVG images on the Jenkins controller file system.

VendorProductVersions

Jenkins project

Jenkins Embeddable Build Status Plugin

affected
unspecified - <= 2.0.3

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now