CVE-2019-10436Path Traversal in Jenkins Google Oauth Credentials

CWE-22Path Traversal4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.1%
top 65.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credentials in Jenkins to obtain the contents of any file on the Jenkins master.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

🔴Vulnerability Details

2
OSV
Improper Limitation of a Pathname to a Restricted Directory in Jenkins Google OAuth Credentials Plugin2022-05-24
GHSA
Improper Limitation of a Pathname to a Restricted Directory in Jenkins Google OAuth Credentials Plugin2022-05-24

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2019-10-162019-10-16