← Back to browse · API

CVE-2023-32985

Severity
MEDIUM
CVSS
4.3
EPSS
0.72358
Risk score
42.53
CISA KEV
No
PoC
No
Published
2023-05-16
Modified
2025-01-23
First seen
2026-08-07
Aliases
EUVD-2023-1600, GHSA-PP8M-PRR7-WR8W
Products
Jenkins Project:Jenkins Sidebar Link Plugin 0 ≤2.2.1
Sources
euvd EUVD-2023-1600

Description

Jenkins Sidebar Link Plugin 2.2.1 and earlier does not restrict the path of files in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

References