GHSA-hrmj-8fm9-cg8xHighCVSS 8.8
Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal...
🔗 CVE IDs covered (1)
📋 Description
Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code execution.