CVE-2023-40338: Jenkins Folders

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log file when attempting to access the Scan Organization Folder Log if no logs are available, exposing information about the Jenkins controller file system.

Affected products

  • Jenkins Folders: up to and including 6.846.v23698686f0f6

Published 2023-08-16. Last modified 2026-06-17.