CVE-2018-1999002

CVE-2018-1999002

A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework’s org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the Jenkins master file system that the Jenkins master has access to.

Source: CVE-2018-1999002

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다