Description
Jenkins Doktor Plugin 0.4.1 and earlier implements functionality that allows agent processes to render files on the controller as Markdown or Asciidoc, and error messages allow attackers able to control agent processes to determine whether a file with a given name exists.
Remediation
References
https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2548
Related Vulnerabilities
CVE-2023-26487 Vulnerability in npm package vega-functions
CVE-2023-37911 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2022-24762 Vulnerability in npm package sysend
CVE-2023-29527 Vulnerability in maven package org.xwiki.platform:xwiki-platform-appwithinminutes-ui
CVE-2017-2638 Vulnerability in maven package org.infinispan:infinispan-compatibility-mode-it