Back to search
CVE-2023-32986
Published: May 16, 2023
Modified: Jan 23, 2025
PUBLISHED
Description
Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File Parameters, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.
| Vendor | Product | Versions |
|---|---|---|
Jenkins Project | Jenkins File Parameter Plugin | affected 0 - <= 285.v757c5b_67a_c25 |
References
Jenkins Security Advisory 2023-05-16
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now