Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
CVSS
No CVSS.
References
Configurations
No configuration.
History
19 Jun 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-19 21:15
Updated : 2023-06-19 21:15
NVD link : CVE-2023-3315
Mitre link : CVE-2023-3315
JSON object : View
Products Affected
No product.
CWE
No CWE.