QID 996976
Date Published: 2024-01-31
QID 996976: Java (Maven) Security Update for org.jenkins-ci.plugins:jobConfigHistory (GHSA-cgh7-rgqg-hrcx)
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file called 'history.xml'.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-cgh7-rgqg-hrcx for updates and patch information.
Vendor References
- GHSA-cgh7-rgqg-hrcx -
github.com/advisories/GHSA-cgh7-rgqg-hrcx
CVEs related to QID 996976
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cgh7-rgqg-hrcx | org.jenkins-ci.plugins:jobConfigHistory |
|