← Back

CVE-2022-25204

nvd nist
Published: Feb 15, 2022Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

Jenkins Doktor Plugin 0.4.1 and earlier implements functionality that allows agent processes to render files on the controller as Markdown or Asciidoc, and error messages allow attackers able to control agent processes to determine whether a file with a given name exists.

Affected (1)

Products: Jenkins: Doktor
1 product
Doktor
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.4.1

References (2)

Source: jenkinsci-cert@googlegroups.com
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory

Timeline

No history available yet.