Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Jenkins Semantic Versioning Plugin 1.13 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitations about the file path that can be parsed, allowing attackers able to control agent processes to have Jenkins parse a crafted file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Jenkins Plugin Semantic Versioning 安全漏洞
Vulnerability Description
Jenkins和Jenkins Plugin都是Jenkins开源的产品。Jenkins是一个应用软件。一个开源自动化服务器Jenkins提供了数百个插件来支持构建,部署和自动化任何项目。Jenkins Plugin是一个应用软件。 Jenkins Plugin Semantic Versioning 存在安全漏洞,该漏洞源于能够控制代理进程的攻击者可以利用该漏洞从 Jenkins 控制器或服务器端请求伪造中提取机密。该漏洞影响以下组件:Semantic Versioning Plugin 1.13 及之
CVSS Information
N/A
Vulnerability Type
N/A