Vulnerabilities (CVE)

Filtered by vendor Jenkins Subscribe
Filtered by product Scriptler
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-50764 1 Jenkins 1 Scriptler 2023-12-18 N/A 8.1 HIGH
Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing attackers with Scriptler/Configure permission to delete arbitrary files on the Jenkins controller file system.