356
VMScore

CVE-2018-1000862

Published: 10/12/2018 Updated: 08/05/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

An information exposure vulnerability exists in Jenkins 2.153 and previous versions, LTS 2.138.3 and previous versions in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the duration of the build using the workspace browser.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins jenkins

redhat openshift container platform 3.11

Vendor Advisories

An information exposure vulnerability exists in Jenkins 2153 and earlier, LTS 21383 and earlier in DirectoryBrowserSupportjava that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the duration of the build using the workspace browser ...