Collected research
Excessive Expansion: Uncovering Critical Security Vulnerabilities in Jenkins
Two vulnerabilities in Jenkins' built-in command line interface. The args4j parser expands any argument beginning with @ by reading the named file and splitting it into arguments, so a command that echoes unresolved arguments leaks arbitrary file contents to read-only and, in some configurations, anonymous users, reaching credentials and hence code execution (CVE-2024-23897).
Record
- Researcher
- Yaniv Nizry
- Published by
- Sonar
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Yaniv Nizry, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .