CVE-2018-6356

Description

Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not have access to. On Windows, any file accessible to the Jenkins master process could be downloaded. On other operating systems, any file within the Jenkins home directory accessible to the Jenkins master process could be downloaded.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
37.846

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Jenkins 2.99Windows
Vulnerabilities CVE-2018-1000067,CVE-2018-1000068,CVE-2018-6356 are fixed in Jenkins-Core 2.89.4Windows
Vulnerabilities CVE-2018-1000067,CVE-2018-1000068,CVE-2018-6356 are fixed in Jenkins-Core 2.107Windows
Multiple vulnerabilities affected in Jenkins 2.99 (For Ubuntu)Linux
Multiple vulnerabilities affected in Jenkins 2.99 (For Debian)Linux
Multiple vulnerabilities affected in Jenkins 2.99 (For Centos)Linux
Multiple vulnerabilities affected in Jenkins 2.99 (For RedHat)Linux
Multiple vulnerabilities affected in Jenkins 2.99 (For Suse)Linux
Vulnerabilities CVE-2018-1000067,CVE-2018-1000068,CVE-2018-6356 are fixed in Jenkins-Core for Linux 2.89.4Linux
Vulnerabilities CVE-2018-1000067,CVE-2018-1000068,CVE-2018-6356 are fixed in Jenkins-Core for Linux 2.107Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234