Description
Jenkins Doktor Plugin 0.4.1 and earlier implements functionality that allows agent processes to render files on the controller as Markdown or Asciidoc, and error messages allow attackers able to control agent processes to determine whether a file with a given name exists.
Remediation
References
https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2548
Related Vulnerabilities
CVE-2022-31103 Vulnerability in npm package lettersanitizer
CVE-2023-22457 Vulnerability in maven package org.xwiki.contrib:application-ckeditor-ui
CVE-2023-36480 Vulnerability in maven package com.aerospike:aerospike-client
CVE-2020-27838 Vulnerability in maven package org.keycloak:keycloak-server-spi-private
CVE-2023-34467 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livetable-ui