SB2022021719 - Security features bypass in Jenkins Doktor plugin



SB2022021719 - Security features bypass in Jenkins Doktor plugin

Published: February 17, 2022

Security Bulletin ID SB2022021719
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security features bypass (CVE-ID: CVE-2022-25204)

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the affected plugin implements functionality that allows agent processes to render files on the controller as Markdown or Asciidoc. A remote user can determine whether a file with a given name exists.


Remediation

Install update from vendor's website.