CVE-2018-1000068

Description

An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the Jenkins home directory is on a case-insensitive file system.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.309

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Jenkins 2.89.3Windows
Vulnerabilities CVE-2018-1000067,CVE-2018-1000068,CVE-2018-6356 are fixed in Jenkins-Core 2.89.4Windows
Vulnerabilities CVE-2018-1000067,CVE-2018-1000068,CVE-2018-6356 are fixed in Jenkins-Core 2.107Windows
Multiple vulnerabilities affected in Jenkins 2.89.3 (For Ubuntu)Linux
Multiple vulnerabilities affected in Jenkins 2.89.3 (For Debian)Linux
Multiple vulnerabilities affected in Jenkins 2.89.3 (For Centos)Linux
Multiple vulnerabilities affected in Jenkins 2.89.3 (For RedHat)Linux
Multiple vulnerabilities affected in Jenkins 2.89.3 (For Suse)Linux
Vulnerabilities CVE-2018-1000067,CVE-2018-1000068,CVE-2018-6356 are fixed in Jenkins-Core for Linux 2.89.4Linux
Vulnerabilities CVE-2018-1000067,CVE-2018-1000068,CVE-2018-6356 are fixed in Jenkins-Core for Linux 2.107Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234