CVE-2024-5273
MEDIUMJenkins Report Info Plugin < 1.2 - Path Traversal via Workspace Directory
Title source: llmDescription
Jenkins Report Info Plugin 1.2 and earlier does not perform path validation of the workspace directory while serving report files, allowing attackers with Item/Configure permission to retrieve Surefire failures, PMD violations, Findbugs bugs, and Checkstyle errors on the controller file system by editing the workspace path.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://www.jenkins.io/security/advisory/2024-05-24/#SECURITY-3070
Scores
CVSS v3
4.3
EPSS
0.0013
EPSS Percentile
31.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (2)
jenkins/report_info
< 1.2
org.jenkins-ci.plugins/report-info
0Maven
Published
May 24, 2024
Tracked Since
Feb 18, 2026