CVE-2022-45388

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/11/2022
Last modified:
30/04/2025

Description

Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers to read arbitrary files with '.xml' extension on the Jenkins controller file system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:config_rotator:*:*:*:*:*:jenkins:*:* 2.0.1 (including)