CVE-2018-1999002 is an arbitrary file read vulnerability in the Stapler web framework used by Jenkins 2.132 and earlier, and 2.121.1 and earlier, as well as Oracle Communications Cloud Native Core Automated Test Suite. This high-severity vulnerability (CVSS 7.5) allows unauthenticated attackers to send crafted HTTP requests to read any file on the Jenkins master file system. While the EPSS score indicates a high likelihood of exploitation, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei), or significant community discussion or media coverage for this specific file read vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.121.1CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:* | ||
>= 2.122, <= 2.132CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:* | ||
1.9.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.