CVE-2022-28148

CWE-22Path Traversal5 documents5 sources
Severity
6.5MEDIUM
EPSS
0.4%
top 42.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 29
Latest updateMar 30

Description

The file browser in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Item/Read permission to obtain the contents of arbitrary files on Windows controllers.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

🔴Vulnerability Details

3
GHSA
Path traversal vulnerability on Windows in Jenkins Continuous Integration with Toad Edge Plugin2022-03-30
OSV
Path traversal vulnerability on Windows in Jenkins Continuous Integration with Toad Edge Plugin2022-03-30
CVEList
CVE-2022-28148: The file browser in Jenkins Continuous Integration with Toad Edge Plugin 22022-03-29

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2022-03-292022-03-29
CVE-2022-28148 (MEDIUM CVSS 6.5) | The file browser in Jenkins Continu | cvebase.io