Medium severity4.3NVD Advisory· Published Jun 19, 2023· Updated Jun 17, 2026
CVE-2023-3315
CVE-2023-3315
Description
Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:teamconcertMaven | < 2.4.2 | 2.4.2 |
Affected products
2- Range: 0
Patches
Vulnerability mechanics
References
4News mentions
1- Jenkins Security Advisory 2023-06-14Jenkins Security Advisories · Jun 14, 2023