CVE-2018-1999002: Input Validation
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the Jenkins master file system that the Jenkins master has access to.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1999002?
CVE-2018-1999002 is considered a medium severity vulnerability allowing arbitrary file reads.
How do I fix CVE-2018-1999002?
To fix CVE-2018-1999002, upgrade Jenkins to version 2.132 or later, or to version 2.121.2.
What versions of Jenkins are affected by CVE-2018-1999002?
Versions 2.132 and earlier, and 2.121.1 and earlier of Jenkins are affected by CVE-2018-1999002.
What type of vulnerability is CVE-2018-1999002?
CVE-2018-1999002 is an arbitrary file read vulnerability in the Stapler web framework of Jenkins.
Can CVE-2018-1999002 be exploited remotely?
Yes, CVE-2018-1999002 can be exploited remotely through crafted HTTP requests.