CVE Published: 16/05/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: jenkins |
Vendor: Jenkins Project |
Product: Jenkins Sidebar Link Plugin Status : PUBLISHED
CVE-2023-32985 Description
Jenkins Sidebar Link Plugin 2.2.1 and earlier does not restrict the path of files in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.