CVE-2018-1000862
Last modified
CVE-2018-1000862 is a vulnerability of currently unknown severity. An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the duration of the build using the workspace browser.. EPSS estimates a 1.37% chance of exploitation in the next 30 days.
Description
An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the duration of the build using the workspace browser.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Jenkins | <= 2.138.3 |
| Jenkins | Jenkins | <= 2.153 |
| Redhat | Openshift Container Platform | 3.11 |
References
- http://www.securityfocus.com/bid/106176Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHBA-2019:0024Third Party Advisory
- http://www.securityfocus.com/bid/106176Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHBA-2019:0024Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1000862?
How severe is CVE-2018-1000862?
How do I fix CVE-2018-1000862?
Are you affected by CVE-2018-1000862?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
