CVE-2018-1000068
An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the…
Does this matter?
Lower severity and a low EPSS score (1.96%). Track it; it rarely justifies an emergency change on its own.
Description
An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the Jenkins home directory is on a case-insensitive file system.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.96% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- jenkins/jenkins · oracle/communications cloud native core automated test suite
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/103101Broken Link
- https://jenkins.io/security/advisory/2018-02-14/#SECURITY-717Vendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/103101Broken Link
- https://jenkins.io/security/advisory/2018-02-14/#SECURITY-717Vendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.