First published: Wed Aug 07 2019(Updated: )
An arbitrary file read vulnerability in Jenkins File System SCM Plugin 2.1 and earlier allows attackers able to configure jobs in Jenkins to obtain the contents of any file on the Jenkins master.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins File System Scm | <=2.1 | |
maven/hudson.plugins.filesystem_scm:filesystem_scm | <=2.1 | |
<=2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-10375.
The title of this vulnerability is 'An arbitrary file read vulnerability in Jenkins File System SCM Plugin 2.1 and earlier allows attackers to obtain the contents of any file on the Jenkins master.'
The severity level of CVE-2019-10375 is medium.
CVE-2019-10375 allows attackers who are able to configure jobs in Jenkins to obtain the contents of any file on the Jenkins master.
Yes, there are security advisories related to CVE-2019-10375. You can find them at the following links: [http://www.openwall.com/lists/oss-security/2019/08/07/1](http://www.openwall.com/lists/oss-security/2019/08/07/1) and [https://jenkins.io/security/advisory/2019-08-07/#SECURITY-569](https://jenkins.io/security/advisory/2019-08-07/#SECURITY-569).