CVE Published: 24/01/2024 |
CVE Updated: 18/10/2024 |
CVE Year: 2024 Source: jenkins |
Vendor: Jenkins Project |
Product: Jenkins Git server Plugin Status : PUBLISHED
CVE-2024-23899 Description
Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an \'@\' character followed by a file path in an argument with the file\'s contents, allowing attackers with Overall/Read permission to read content from arbitrary files on the Jenkins controller file system.