GHSA-xcrr-x93h-rv4v
HIGHCVE-2023-50764Jenkins Scriptler Plugin 342.v6a89fd40f466 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing attackers with Scriptler/Configure permission to delete arbitrary files on the Jenkins controller file system.
- Affected
- <= 342.v6a
- Fixed in
- not stated
- Published
- 2023-12-13
- Source
- github