Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-6356

Опубликовано: 20 фев. 2018
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Средний

Описание

Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not have access to. On Windows, any file accessible to the Jenkins master process could be downloaded. On other operating systems, any file within the Jenkins home directory accessible to the Jenkins master process could be downloaded.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*
Версия до 2.107 (исключая)
Конфигурация 2
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
Версия до 2.89.4 (исключая)
Конфигурация 3
cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.37846
Средний

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 8 лет назад

Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not have access to. On Windows, any file accessible to the Jenkins master process could be downloaded. On other operating systems, any file within the Jenkins home directory accessible to the Jenkins master process could be downloaded.

CVSS3: 6.5
redhat
почти 8 лет назад

Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not have access to. On Windows, any file accessible to the Jenkins master process could be downloaded. On other operating systems, any file within the Jenkins home directory accessible to the Jenkins master process could be downloaded.

CVSS3: 6.5
debian
почти 8 лет назад

Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly pr ...

CVSS3: 6.5
github
больше 3 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Jenkins

EPSS

Процентиль: 97%
0.37846
Средний

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-22