4
CVSSv2

CVE-2018-1999006

Published: 23/07/2018 Updated: 08/05/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

A exposure of sensitive information vulnerability exists in Jenkins 2.132 and previous versions, 2.121.1 and previous versions in Plugin.java that allows malicious users to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date of the most recent installation/upgrade.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins jenkins

Vendor Advisories

A exposure of sensitive information vulnerability exists in Jenkins 2132 and earlier, 21211 and earlier in Pluginjava that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date of the most recent installation/upgrade ...
Files indicating when a plugin JPI file was last extracted into a subdirectory of plugins/ in the Jenkins home directory were accessible via HTTP by users with Overall/Read permission before Jenkins 2133 This allowed unauthorized users to determine the likely install date of a given plugin ...