Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.
Remediation
References
Related Vulnerabilities
WordPress Plugin Cookie Information-Free GDPR Consent Solution Cross-Site Scripting (1.5.5)
Jenkins Incorrect Authorization Vulnerability (CVE-2021-21692 )
WordPress Plugin Contact Form 7 Dynamic Text Extension Cross-Site Scripting (2.0.2.1)
XWiki Missing Authorization Vulnerability (CVE-2023-37910)
RubyGems 7PK - Security Features Vulnerability (CVE-2015-3900)