7.5
CVSSv3

CVE-2022-45388

Published: 15/11/2022 Updated: 01/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Jenkins Config Rotator Plugin 2.0.1 and previous versions does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated malicious users to read arbitrary files with '.xml' extension on the Jenkins controller file system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins config rotator