CVE Database
/

CVE-2023-32986

Back to search

CVE-2023-32986

Published: May 16, 2023

Modified: Jan 23, 2025

PUBLISHED

Description

Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File Parameters, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.

VendorProductVersions

Jenkins Project

Jenkins File Parameter Plugin

affected
0 - <= 285.v757c5b_67a_c25

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now