CVE-2018-1000169 Information
Feb 14, 2021
cve
Description
An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older LTS 2.107.1 and older in CLICommand.java and ViewOptionHandler.java that allows unauthorized attackers to confirm the existence of agents or views with an attacker-specified name by sending a CLI command to Jenkins.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://access.redhat.com/errata/RHBA-2018:1816 https://jenkins.io/security/advisory/2018-04-11/SECURITY-754
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: