Showing 2 vulnerabilities on this page for Jenkins External Workspace Manager Plugin

Signals CISA KEV Ransomware Nuclei
Jenkins project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Generated title:Jenkins External Workspace Manager Plugin Missing Permission Check Information Disclosure

Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in workspaces they are not authorized to access.

CWE-862Aug 5, 2026
CVSS4.3v3.1EPSS0.221%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Jenkins External Workspace Manager Plugin Path Traversal in exwsAllocate Pipeline Step

Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code execution.

CWE-22Jun 24, 2026
CVSS8.8v3.1EPSS0.595%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX