Description
Jenkins Doktor Plugin 0.4.1 and earlier implements functionality that allows agent processes to render files on the controller as Markdown or Asciidoc, and error messages allow attackers able to control agent processes to determine whether a file with a given name exists.
Remediation
References
https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2548
Related Vulnerabilities
CVE-2023-32314 Vulnerability in maven package org.webjars.npm:vm2
CVE-2023-29507 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2022-45210 Vulnerability in maven package org.jeecgframework.boot:jeecg-module-system
CVE-2022-1295 Vulnerability in maven package org.webjars.bowergithub.alvarotrigo:fullpage.js
CVE-2022-1291 Vulnerability in npm package tableexport.jquery.plugin