CVE-2018-6356 is a path traversal vulnerability affecting Jenkins versions prior to 2.107 and Jenkins LTS prior to 2.89.4, as well as Oracle Communications Cloud Native Core Automated Test Suite. It allows authenticated users with read permissions to download arbitrary files from the Jenkins master, including sensitive system files on Windows and files within the Jenkins home directory on other operating systems. The vulnerability has a CVSS score of 6.5 (Medium) due to its network-based attack vector and high confidentiality impact, but requires low privileges and has low attack complexity. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.107CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:* | ||
< 2.89.4CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* | ||
1.9.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.