CVE-2015-1807: Path Traversal
Directory traversal vulnerability in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with certain permissions to read arbitrary files via a symlink, related to building artifacts.
Other sources
This vulnerability allows users with the job configuration privilege or users with commit access to the build script to access arbitrary files/directories on the master, resulting in the exposure of sensitive information, such as encryption keys.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-02-27
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1807?
CVE-2015-1807 has been classified as a moderate severity vulnerability.
How do I fix CVE-2015-1807?
To mitigate CVE-2015-1807, update Jenkins to version 1.601 or later.
What type of users are affected by CVE-2015-1807?
CVE-2015-1807 affects remote authenticated users with job configuration privileges.
What versions of Jenkins are impacted by CVE-2015-1807?
Jenkins versions prior to 1.600 and LTS versions before 1.596.1 are impacted by CVE-2015-1807.
What can attackers do with CVE-2015-1807?
Attackers can exploit CVE-2015-1807 to read arbitrary files on the server via a symlink.