CVE-2018-1999006 is a sensitive information exposure vulnerability affecting Jenkins 2.132 and earlier, and 2.121.1 and earlier. It allows authenticated attackers to determine the last extraction date of plugin HPI/JPI files, typically indicating the most recent installation or upgrade. Rated Medium (CVSS 4.3), this vulnerability has a low impact on confidentiality with no integrity or availability impact, and requires low privileges for exploitation over the network. There is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.121.1CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* | ||
<= 2.132CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.