#VU79886 Path traversal in Folders - CVE-2023-40338
Published: August 23, 2023
Folders
Jenkins
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to the affected plugin displays an error message that includes an absolute path of a log file when attempting to access the Scan Organization Folder Log if no logs are available. A remote user can send a specially crafted HTTP request and read arbitrary files on the system.