SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Jenkins plugin Extended Choice Parameter Directory Traversal 2

Category: WEB-ATTACKS      

An issue was discovered in the Extended Choice Parameter (aka extended-choice-parameter) plugin 0.64 for Jenkins 2.89.3. The PATH_INFO filename is vulnerable to path traversal attacks via ..\ sequences to the /plugin/extended-choice-parameter/js/ URI.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6356


Relevant Information