#VU85803 Information disclosure in Log Command - CVE-2024-23904
Published: January 25, 2024
Log Command
Jenkins
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected plugin does not disable a feature of its command parser that replaces an "@" character followed by a file path in an argument with the file’s contents. A remote attacker can gain unauthorized access to sensitive information on the system.