CVE-2018-1999002
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 86.6%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the Jenkins master file system that the Jenkins master has access to.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 86.64% probability · 100th percentile
- CISA KEV
- Not listed
- Affected
- jenkins/jenkins · oracle/communications cloud native core automated test suite
- Source
- cve@mitre.org
References
- https://jenkins.io/security/advisory/2018-07-18/#SECURITY-914Mitigation, Vendor Advisory
- https://www.exploit-db.com/exploits/46453/Exploit, Third Party Advisory, VDB Entry
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://jenkins.io/security/advisory/2018-07-18/#SECURITY-914Mitigation, Vendor Advisory
- https://www.exploit-db.com/exploits/46453/Exploit, Third Party Advisory, VDB Entry
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.