CVE-2024-5273
Last modified
CVE-2024-5273 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Jenkins Report Info Plugin 1.2 and earlier does not perform path validation of the workspace directory while serving report files, allowing attackers with Item/Configure permission to retrieve Surefire failures, PMD violations, Findbugs bugs, and Checkstyle errors on the controller file system by editing the workspace path.. EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
Jenkins Report Info Plugin 1.2 and earlier does not perform path validation of the workspace directory while serving report files, allowing attackers with Item/Configure permission to retrieve Surefire failures, PMD violations, Findbugs bugs, and Checkstyle errors on the controller file system by editing the workspace path.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Report Info | <= 1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-5273?
How severe is CVE-2024-5273?
How do I fix CVE-2024-5273?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-52714Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buff…9.8
- CVE-2024-5272Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <=…4.3
- CVE-2024-52723In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd fil…9.8
- CVE-2024-52724ZZCMS 2023 was discovered to contain a SQL injection vulnera…9.8
- CVE-2024-52725SemCms v4.8 was discovered to contain a SQL injection vulner…4.9
- CVE-2024-52726CRMEB v5.4.0 is vulnerable to Arbitrary file read in the sav…7.5
- CVE-2024-52732Incorrect access control in wms-Warehouse management system-…9.1
- CVE-2024-52739D-LINK DI-8400 v16.07.26A1 was discovered to contain multipl…8
- CVE-2024-5274Type Confusion in V8 in Google Chrome prior to 125.0.6422.11…9.6
- CVE-2024-5275A hard-coded password in the FileCatalyst TransferAgent can …7.8
- CVE-2024-52754D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffe…4.9
- CVE-2024-52755D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffe…4.9
Are you affected by CVE-2024-5273?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
