CVE-2018-1000068 Information
Feb 14, 2021
cve
Description
An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier and LTS 2.89.3 and earlier that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible if the Jenkins home directory is on a case-insensitive file system.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
http://www.securityfocus.com/bid/103101 https://jenkins.io/security/advisory/2018-02-14/SECURITY-717
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: