An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the duration of the build using the workspace browser.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-4184 An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the duration of the build using the workspace browser.
Github GHSA Github GHSA GHSA-hph9-9vcq-f7gp Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T12:47:57.398Z

Reserved: 2018-12-10T00:00:00

Link: CVE-2018-1000862

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-12-10T14:29:01.463

Modified: 2024-11-21T03:40:31.197

Link: CVE-2018-1000862

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-12-05T00:00:00Z

Links: CVE-2018-1000862 - Bugzilla

cve-icon OpenCVE Enrichment

No data.