CVE-2018-1000148

MEDIUM

Jenkins Copy To Slave Plugin <1.4.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

An exposure of sensitive information vulnerability exists in Jenkins Copy To Slave Plugin version 1.4.4 and older in CopyToSlaveBuildWrapper.java that allows attackers with permission to configure jobs to read arbitrary files from the Jenkins master file system.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0009
EPSS Percentile 26.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
jenkins/copy_to_slave < 1.4.4
org.jenkins-ci.plugins/copy-to-slave 0Maven
Published Apr 05, 2018
Tracked Since Feb 18, 2026