A path traversal vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java that allows attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-01-09T23:00:00

Updated: 2024-08-05T12:40:47.025Z

Reserved: 2019-01-09T00:00:00

Link: CVE-2018-1000406

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-01-09T23:29:02.263

Modified: 2019-05-08T22:23:28.797

Link: CVE-2018-1000406

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-10-10T00:00:00Z

Links: CVE-2018-1000406 - Bugzilla