jenkins: workspace browser allowed accessing files outside the workspace (SECURITY-904)
Published Dec 10, 2018
4.3
MEDIUMCVSS 3.0
EPSS 1.37%
Description
An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the duration of the build using the workspace browser.
Affected products
No data.
No data.
Red Hat OpenShift Container Platform 3.11
jenkins-0:2.138.4.1544416383-1.el7
Fixed · RHBA-2019:0024
Red Hat OpenShift Container Platform 3.10
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.2
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.3
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.4
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.5
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.6
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.7
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.9
jenkins
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | jenkins-0:2.138.4.1544416383-1.el7 | Fixed | RHBA-2019:0024 |
| Red Hat OpenShift Container Platform 3.10 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.2 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.3 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.4 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.5 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.6 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.7 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.9 | jenkins | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- http://www.securityfocus.com/bid/106176 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHBA-2019:0024 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-1000862 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1656945 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4184 Advisory
- https://github.com/advisories/GHSA-hph9-9vcq-f7gp Advisory
- https://github.com/jenkinsci/jenkins/commit/c19cc705688cfffa4fe735e0edbe84862b6c135f
- https://jenkins.io/security/advisory/2018-12-05/#SECURITY-904 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000862
- https://www.cve.org/CVERecord?id=CVE-2018-1000862
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/106176 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/errata/RHBA-2019:0024 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2018-1000862 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1656945 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4184 | Advisory | |
| https://github.com/advisories/GHSA-hph9-9vcq-f7gp | Advisory | |
| https://github.com/jenkinsci/jenkins/commit/c19cc705688cfffa4fe735e0edbe84862b6c135f | ||
| https://jenkins.io/security/advisory/2018-12-05/#SECURITY-904 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1000862 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1000862 |
Change history (0)
No recorded changes yet.