

A path traversal vulnerability exists in the Stapler web framework used by Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/org/kohsuke/stapler/, groovy/src/main/java/org/kohsuke/stapler/jelly/groovy/, jelly/src/main/java/org/kohsuke/stapler/jelly/, jruby/src/main/java/org/kohsuke/stapler/jelly/jruby/, jsp/src/main/java/org/kohsuke/stapler/jsp/ that allows attackers to render routable objects using any view in Jenkins, exposing internal information about those objects not intended to be viewed, such as their toString() representation.

Source: CVE-2018-1000997

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다