Description
A missing permission check in Jenkins Code Dx Plugin 3.1.0 and earlier allows attackers with Item/Read permission to check for the existence of an attacker-specified file path on an agent file system.
Remediation
References
https://www.jenkins.io/security/advisory/2023-05-16/#SECURITY-3145
Related Vulnerabilities
CVE-2023-25499 Vulnerability in maven package com.vaadin:flow-server
CVE-2023-28640 Vulnerability in maven package io.apiman:apiman-manager-api-rest-impl
CVE-2022-37865 Vulnerability in maven package org.apache.ivy:ivy
CVE-2021-42010 Vulnerability in maven package org.apache.heron:heron-api
CVE-2023-50765 Vulnerability in maven package org.jenkins-ci.plugins:scriptler