Vulnerabilities
Vulnerable Software
Jenkins:  >> Jenkins  >> 2.104  Security Vulnerabilities
Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not have access to. On Windows, any file accessible to the Jenkins master process could be downloaded. On other operating systems, any file within the Jenkins home directory accessible to the Jenkins master process could be downloaded.
CVSS Score
6.5
EPSS Score
0.378
Published
2018-02-20
An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.
CVSS Score
5.3
EPSS Score
0.004
Published
2018-02-16
An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the Jenkins home directory is on a case-insensitive file system.
CVSS Score
5.3
EPSS Score
0.003
Published
2018-02-16


Contact Us

Shodan ® - All rights reserved