file-parameters is vulnerable to Path Traversal
88
High Risk
A @DataBoundConstructor path in File Parameter Plugin stores uploaded files using a parameter name as a path without applying the existing safety validation. Attackers able to submit certain forms can write files to arbitrary controller filesystem locations, including paths that can lead to code execution. The fix applies the same parameter name validation in that constructor.
You are affected if you are using a version that falls within the vulnerable range and users can submit forms that bind File Parameter plugin definitions.
file-parameters is vulnerable to Path Traversal in versions 0.0.1 - 425.
Upgrade the io.jenkins.plugins:file-parameters library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.