CVE Published: 19/06/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: jenkins |
Vendor: Jenkins Project |
Product: Jenkins Team Concert Plugin Status : PUBLISHED
CVE-2023-3315 Description
Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.