CVE-2023-24449: Jenkins Pwauth Security Realm

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

Jenkins PWauth Security Realm Plugin 0.4 and earlier does not restrict the names of files in methods implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

Affected products

  • Jenkins Pwauth Security Realm: up to and including 0.4

Published 2023-01-26. Last modified 2026-06-17.