First published: Thu Feb 09 2017(Updated: )
Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbitrary directories and read arbitrary files via unspecified form fields.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.tupilabs.image_gallery:image-gallery | <1.4 | 1.4 |
Jenkins | <1.4 | |
<1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4987 is considered a medium severity vulnerability due to its potential to allow unauthorized file access.
To fix CVE-2016-4987, upgrade the Image Gallery plugin to version 1.4 or later.
CVE-2016-4987 is a directory traversal vulnerability that affects the Image Gallery plugin in Jenkins.
Versions of Jenkins that use Image Gallery plugin versions prior to 1.4 are affected by CVE-2016-4987.
Yes, CVE-2016-4987 can be exploited remotely by attackers to list directories and read files.