GHSA-hrmj-8fm9-cg8xHighCVSS 8.8

Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal...

Published
June 24, 2026
Last Modified
June 24, 2026

🔗 CVE IDs covered (1)

📋 Description

Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code execution.

🔗 References (3)