Description
Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
Remediation
References
https://www.jenkins.io/security/advisory/2023-06-14/#SECURITY-2932
Related Vulnerabilities
CVE-2017-5929 Vulnerability in maven package ch.qos.logback:logback-classic
CVE-2014-8152 Vulnerability in maven package org.apache.santuario:xmlsec
CVE-2020-1698 Vulnerability in maven package org.keycloak:keycloak-authz-client
CVE-2016-6813 Vulnerability in maven package org.apache.cloudstack:cloudstack
CVE-2011-1772 Vulnerability in maven package org.apache.struts.xwork:xwork-core