CVE-2018-1000175: Path Traversal
A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build step to override arbitrary files on the Jenkins master.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1000175?
CVE-2018-1000175 is a path traversal vulnerability that exists in Jenkins HTML Publisher Plugin 1.15 and older.
What is the severity of CVE-2018-1000175?
The severity of CVE-2018-1000175 is medium with a CVSS score of 6.5.
How does CVE-2018-1000175 affect Jenkins HTML Publisher Plugin?
CVE-2018-1000175 allows attackers who are able to configure the HTML Publisher build step to override arbitrary files on the Jenkins master.
How can I mitigate CVE-2018-1000175?
To mitigate CVE-2018-1000175, it is recommended to update Jenkins HTML Publisher Plugin to version 1.16 or later.
Where can I find more information about CVE-2018-1000175?
More information about CVE-2018-1000175 can be found at the following link: [CVE-2018-1000175](https://jenkins.io/security/advisory/2018-04-16/).