CVE-2018-1000175

CWE-22Path Traversal5 documents5 sources
Severity
6.5MEDIUM
EPSS
0.3%
top 43.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 8
Latest updateMay 14

Description

A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build step to override arbitrary files on the Jenkins master.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

3
OSV
Jenkins HTML Publisher Plugin path traversal vulnerability2022-05-14
GHSA
Jenkins HTML Publisher Plugin path traversal vulnerability2022-05-14
CVEList
CVE-2018-1000175: A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 12018-05-08

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2018-04-162018-04-16
CVE-2018-1000175 (MEDIUM CVSS 6.5) | A path traversal vulnerability exis | cvebase.io