QID 996878
Date Published: 2024-01-25
QID 996878: Java (Maven) Security Update for org.jenkins-ci.plugins:git-server (GHSA-vph5-2q33-7r9h)
Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file system.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-vph5-2q33-7r9h for updates and patch information.
Vendor References
- GHSA-vph5-2q33-7r9h -
github.com/advisories/GHSA-vph5-2q33-7r9h
CVEs related to QID 996878
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vph5-2q33-7r9h | org.jenkins-ci.plugins:git-server |
|