CVE-2018-1000406: Path Traversal
A path traversal vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java that allows attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000406?
CVE-2018-1000406 is rated as a medium severity vulnerability.
How do I fix CVE-2018-1000406?
To fix CVE-2018-1000406, upgrade Jenkins to version 2.146 or later if using versions up to 2.145.
What versions are affected by CVE-2018-1000406?
CVE-2018-1000406 affects Jenkins versions 2.145 and earlier, and LTS 2.138.1 and earlier.
What impact does CVE-2018-1000406 have?
CVE-2018-1000406 allows attackers with Job/Configure permission to exploit path traversal vulnerabilities.
Who can exploit CVE-2018-1000406?
Only attackers with Job/Configure permission can exploit CVE-2018-1000406.