1 results (0.005 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

24 Jan 2024 — Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read content from arbitrary files on the Jenkins controller file system. Jenkins Log Command Plugin 1.0.2 y versiones anteriores no desactivan una función de su analizador de comandos que reemplaza un carácter '@' seguido de una ruta de archivo en un argumento con el contenido del ar... • http://www.openwall.com/lists/oss-security/2024/01/24/6 •