Description
A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Item/Read permission to check for the existence of an attacker-specified file path on an agent file system.
Remediation
References
https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3145
Related Vulnerabilities
CVE-2023-46659 Vulnerability in maven package org.jenkins-ci.plugins:trac
CVE-2023-29528 Vulnerability in maven package org.xwiki.commons:xwiki-commons-xml
CVE-2023-37277 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rest-server
CVE-2022-34812 Vulnerability in maven package org.jenkins-ci.plugins:xpath-config-viewer