Vulnerability Details CVE-2022-45388
Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers to read arbitrary files with '.xml' extension on the Jenkins controller file system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.5%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2022-45388
-
cpe:2.3:a:jenkins:config_rotator:-
-
cpe:2.3:a:jenkins:config_rotator:2.0.1