FlawAtlas
Search the atlas
CVE-2023-40338 Moderate

Jenkins Folders Plugin information disclosure vulnerability

Jenkins Folders Plugin displays an error message when attempting to access the Scan Organization Folder Log if no logs are available. In Folders Plugin 6.846.v23698686f0f6 and earlier, this error message includes the absolute path of a log file, exposing information about the Jenkins controller file system. Folders Plugin 6.848.ve3b_fd7839a_81 does not display the absolute path of a log file in the error message.

Exploit probability 0.5%
Published August 16, 2023
Required by Not available
Last source change February 16, 2024

02 / AFFECTED SOFTWARE

Affected packages

Maven org.jenkins-ci.plugins:cloudbees-folder

88 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-36hq-v2fc-rpqp

Jenkins Folders Plugin displays an error message when attempting to access the Scan Organization Folder Log if no logs are available. In Folders Plugin 6.846.v23698686f0f6 and earlier, this error message includes the absolute path of a log file, exposing information about the Jenkins controller file system. Folders Plugin 6.848.ve3b_fd7839a_81 does not display the absolute path of a log file in the error message.

View original source

05 / REFERENCES

Further evidence