CVE-2018-1000406

CVSS v3.0 6.5 (Medium)
65% Progress
CVSS v2.0 4 (Medium)
40% Progress
EPSS 0.06 % (28th)
0.06% Progress
Affected Products 1
Advisories 2

A path traversal vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java that allows attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build.

Weaknesses
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2019-01-09 23:29:02
(5 years ago)
Updated Date
2019-05-08 22:23:28
(5 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins 2.138.1 and prior versions cpe:2.3:a:jenkins:jenkins::*:*:*:lts <= 2.138.1
  Jenkins 2.145 and prior versions cpe:2.3:a:jenkins:jenkins::*:*:*:- <= 2.145
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...