VYPR

External Workspace Manager Plugin

by Jenkins Project

CVEs (1)

  • CVE-2026-57296Jun 24, 2026
    risk 0.00cvss epss

    Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file…