CVE-2018-1999002

EUVD-2022-4954
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the Jenkins master file system that the Jenkins master has access to.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
jenkinsjenkins
𝑥
≤ 2.121.1
jenkinsjenkins
2.122 ≤
𝑥
≤ 2.132
oraclecommunications_cloud_native_core_automated_test_suite
1.9.0
𝑥
= Vulnerable software versions