ZeroHour

CVE-2023-35147

CVSS 3.1
6.5 medium
EPSS
<1%p48
Published
()
Modified
Description

Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attackers with Item/Read permission to obtain the contents of arbitrary files on the Jenkins controller file system.

Vendors
jenkins
Products
aws codecommit trigger
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.