Arbitrary File Read Affecting org.jenkins-ci.plugins:electricflow package, versions [,1.1.33)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.06% (30th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Arbitrary File Read vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-ORGJENKINSCIPLUGINS-6039487
  • published30 Oct 2023
  • disclosed26 Oct 2023
  • creditAndrea Chiera, CloudBees, Inc.

Introduced: 26 Oct 2023

CVE-2023-46655  (opens in a new tab)
CWE-22  (opens in a new tab)

How to fix?

Upgrade org.jenkins-ci.plugins:electricflow to version 1.1.33 or higher.

Overview

org.jenkins-ci.plugins:electricflow is an enterprise-grade DevOps Release Automation platform that simplifies provisioning, build and release of multi-tiered applications.

Affected versions of this package are vulnerable to Arbitrary File Read. CloudBees CD Plugin temporarily copies files from an agent workspace to the controller in preparation for publishing them in the 'CloudBees CD - Publish Artifact' post-build step.CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the temporary directory on the controller when collecting the list of files to publish.This allows attackers able to configure jobs to publish arbitrary files from the Jenkins controller file system to the previously configured CloudBees CD server.

CVSS Scores

version 3.1