Improper Link Resolution Before File Access ('Link Following') Affecting org.jenkins-ci.plugins:scriptler package, versions [,344.v5a_ddb_5f9e685)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGJENKINSCIPLUGINS-6124890
  • published14 Dec 2023
  • disclosed13 Dec 2023
  • creditAndrea Chiera

Introduced: 13 Dec 2023

CVE-2023-50764  (opens in a new tab)
CWE-59  (opens in a new tab)

How to fix?

Upgrade org.jenkins-ci.plugins:scriptler to version 344.v5a_ddb_5f9e685 or higher.

Overview

org.jenkins-ci.plugins:scriptler is a package that allows you to store/edit/execute Groovy scripts on any of the slaves/nodes - no need to copy paste Groovy code anymore. Besides administering your scripts, Scriptler also provides a way to share scripts between users via hosted script catalogs on the internet.

Affected versions of this package are vulnerable to Improper Link Resolution Before File Access ('Link Following') due to insufficient validation of a file name query parameter in an HTTP endpoint. An attacker with Scriptler/Configure permission can delete arbitrary files on the Jenkins controller file system.

CVSS Scores

version 3.1