CVE-2019-10352 is a path traversal vulnerability in Jenkins versions 2.185 and earlier, and LTS 2.176.1 and earlier. Attackers with Job/Configure permissions could exploit this flaw by manipulating file parameters, leading to arbitrary file writes on the Jenkins master when scheduling a build. Rated as MEDIUM severity with a CVSS score of 6.5, this vulnerability requires low privileges and no user interaction, but has a high impact on integrity. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.176.1CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* | ||
<= 2.185CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Improper Limitation of a Pathname to a Restricted Directory in Jenkins
May 24, 2022Jenkins Path Traversal / Arbitrary File Write
Jul 17, 2019Jenkins Path Traversal / Arbitrary File Write
Jul 17, 2019Jenkins Path Traversal / Arbitrary File Write
Jul 17, 2019Jenkins Path Traversal / Arbitrary File Write
Jul 17, 2019Jenkins Path Traversal / Arbitrary File Write
Jul 17, 2019Jenkins Path Traversal / Arbitrary File Write
Jul 17, 2019jenkins: Arbitrary file write vulnerability using file parameter definitions (SECURITY-1424)
Jul 17, 2019