Retour à la veille

CVE-2026-70428

Publié : 5 août 2026
Modifié : 5 août 2026
Lien officiel NVD
Score CVSS
4.3
MEDIUM

Description détaillée

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Références et Patchs