Jenkins AWS CodeCommit Trigger... CVE-2023-35147

- AV AC AU C I A
发布: 2023-06-14
修订: 2024-12-31

Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attackers with Item/Read permission to obtain the contents of arbitrary files on the Jenkins controller file system.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息