Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-46654


Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure jobs to delete arbitrary files on the Jenkins controller file system.


Published

2023-10-25T18:17:40.130

Last Modified

2024-11-21T08:28:59.250

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Primary
    CWE-59

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins cloudbees_cd ≤ 1.1.32 Yes

References