{"id":"GHSA-c7r5-cww9-64q6","summary":"Path traversal in Jenkins Job Configuration History Plugin","details":"Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict the 'name' query parameter when rendering a history entry, allowing attackers to have Jenkins render a manipulated configuration history that was not created by the plugin.","aliases":["CVE-2023-41930"],"modified":"2024-01-30T23:41:38.662198Z","published":"2023-09-06T15:30:26Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-01-30T23:12:08Z","nvd_published_at":"2023-09-06T13:15:09Z","cwe_ids":["CWE-22"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-41930"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2023-09-06/#SECURITY-3233"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/09/06/9"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:jobConfigHistory","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/jobConfigHistory"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1229.v3039470161a_d"}]}],"versions":["1.10","1.11","1.12","1.13","1119.v509e1017356b_","1133.v0f5420f85053","1139.v888b_656ca_f6d","1146.v94c2521f9213","1148.v8607da_ef251e","1155.v28a_46a_cc06a_5","1156.v536a_97b_8d649","1163.ve82c7c6e60a_3","1165.v8cc9fd1f4597","1166.vc9f255f45b_8a","1170.v8a_c085b_dd49c","1171.v04b_66d78555e","1176.v1b_4290db_41a_5","1183.v6e2785ff75e0","1187.v2a_b_1ca_54d18d","1191.v168c8c2b_956a","1198.v4d5736c2308c","1206.vc8967cc8a_2cb_","1207.vd28a_54732f92","1212.vd4470d08ff12","1227.v7a_79fc4dc01f","2.0","2.1","2.1.1","2.10","2.11","2.12","2.13","2.14","2.15","2.16","2.17","2.18","2.18.1","2.18.2","2.18.3","2.19","2.2","2.20","2.21","2.22","2.23","2.23.1","2.24","2.25","2.26","2.27","2.28","2.28.1","2.29","2.29-rc1073.41ef89cf4e15","2.3","2.30","2.31-rc1092.de9e11acbcf3","2.31-rc1098.b666422863b2","2.31-rc1107.2354f08725a_8","2.31-rc1118.fdcd7d8898ff","2.4","2.5","2.6","2.8","2.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 1227.v7a","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-c7r5-cww9-64q6/GHSA-c7r5-cww9-64q6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}