VYPR

External Workspace Manager Plugin

by Jenkins Project

CVEs (2)

  • CVE-2026-57296HigJun 24, 2026
    risk 0.57cvss 8.8epss 0.01

    Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file…

  • CVE-2026-70436MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with…