GHSA-5jp6-w4g2-655cHighCVSS 8.8

A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with...

Published
September 2, 2026
Last Modified
September 2, 2026

🔗 CVE IDs covered (1)

📋 Description

A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arbitrary files on the Jenkins controller's file system.

🔗 References (3)