NA

CVE-2023-46655

Published: 25/10/2023 Updated: 01/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Jenkins CloudBees CD Plugin 1.1.32 and previous versions follows symbolic links to locations outside of the directory from which artifacts are published during the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure jobs to publish arbitrary files from the Jenkins controller file system to the previously configured CloudBees CD server.

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins cloudbees cd