Moderate severityNVD Advisory· Published Aug 16, 2023· Updated Aug 2, 2024
CVE-2023-40338
CVE-2023-40338
Description
Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log file when attempting to access the Scan Organization Folder Log if no logs are available, exposing information about the Jenkins controller file system.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:cloudbees-folderMaven | < 6.848.ve3b | 6.848.ve3b |
Affected products
1- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-36hq-v2fc-rpqpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-40338ghsaADVISORY
- www.jenkins.io/security/advisory/2023-08-16/ghsavendor-advisoryWEB
- www.openwall.com/lists/oss-security/2023/08/16/3ghsaWEB
News mentions
0No linked articles in our index yet.