QID 996980
Date Published: 2024-01-31
QID 996980: Java (Maven) Security Update for org.jenkins-ci.plugins:aws-codecommit-trigger (GHSA-whgj-6m78-2gg9)
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attackers with Item/Read permission to obtain the contents of arbitrary files on the Jenkins controller file system.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-whgj-6m78-2gg9 for updates and patch information.
Vendor References
- GHSA-whgj-6m78-2gg9 -
github.com/advisories/GHSA-whgj-6m78-2gg9
CVEs related to QID 996980
Software Advisories
| Advisory ID | Software | Component | Link |
|---|