cbcvebase.
CVE-2023-46654
published 2023-10-25

CVE-2023-46654: Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of the…

PriorityP349high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
1.35%
68.6th percentile
Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure jobs to delete arbitrary files on the Jenkins controller file system.

Affected

11 ranges
VendorProductVersion rangeFixed in
jenkinscloudbees_cd<= 1.1.32
jenkinscloudbees_cd_plugin
jenkinsedgewall_trac_plugin
jenkinsgithub_plugin
jenkinsgogs_plugin
jenkinsmsteams_webhook_trigger_plugin
jenkinsmultibranch_scan_webhook_trigger_plugin
jenkinsnon-constant_time_webhook_token_comparison_in_gogs_plugin
jenkinswarnings_plugin
jenkinszanata_plugin
jenkins_projectjenkins_cloudbees_cd_plugin<= 1.1.32
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.