CVE-2018-1000068

MEDIUM

Jenkins <2.106-2.89.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the Jenkins home directory is on a case-insensitive file system.

References (3)

Core 3
Core References
Broken Link vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103101
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html

Scores

CVSS v3 5.3
EPSS 0.0031
EPSS Percentile 54.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (4)
jenkins/jenkins < 2.106
jenkins/jenkins < 2.89.3
oracle/communications_cloud_native_core_automated_test_suite 1.9.0
org.jenkins-ci.main/jenkins-core 0 - 2.89.4Maven
Published Feb 16, 2018
Tracked Since Feb 18, 2026