CVE-2024-54004

Publication date

2024-11-27 17:03:51

Family

jenkins

State

PUBLISHED

Description

Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system.