VYPR
Medium severity6.5NVD Advisory· Published Sep 6, 2023· Updated Jun 17, 2026

CVE-2023-41932

CVE-2023-41932

Description

Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowing attackers with to delete attacker-specified directories on the Jenkins controller file system as long as they contain a file called 'history.xml'.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:jobConfigHistoryMaven
< 1229.v3039470161a_d1229.v3039470161a_d

Affected products

2

Patches

Vulnerability mechanics

References

4

News mentions

1