6.5
CVSSv3

CVE-2018-6356

Published: 20/02/2018 Updated: 13/06/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Jenkins prior to 2.107 and Jenkins LTS prior to 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not have access to. On Windows, any file accessible to the Jenkins master process could be downloaded. On other operating systems, any file within the Jenkins home directory accessible to the Jenkins master process could be downloaded.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins jenkins

oracle communications cloud native core automated test suite 1.9.0

Vendor Advisories

Jenkins before 2107 and Jenkins LTS before 2894 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files This allowed users with Overall/Read permission to download files from the Jenkins master they should not have access to On Windows, any file accessible to the Jenkins master p ...