CVE-2018-1000194: Path Traversal
A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000194?
CVE-2018-1000194 is rated as a high severity vulnerability due to its potential to allow unauthorized file access.
How do I fix CVE-2018-1000194?
To fix CVE-2018-1000194, upgrade Jenkins to version 2.121 or later, or LTS to version 2.107.3 or later.
What software is affected by CVE-2018-1000194?
CVE-2018-1000194 affects Jenkins versions up to and including 2.120 and LTS versions up to and including 2.107.2.
What does CVE-2018-1000194 allow an attacker to do?
CVE-2018-1000194 allows attackers to perform path traversal and read or write arbitrary files on the Jenkins master.
Is CVE-2018-1000194 present in Oracle Communications Cloud Native Core Automated Test Suite?
Yes, CVE-2018-1000194 specifically affects Oracle Communications Cloud Native Core Automated Test Suite version 1.9.0.