vulnerability

Jenkins Advisory 2018-05-09: CVE-2018-1000194: Path traversal vulnerability in agent to master security subsystem

Severity
6
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:N)
Published
Jun 5, 2018
Added
Aug 23, 2018
Modified
Aug 11, 2025

Description

A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection.

Solutions

jenkins-lts-upgrade-2_107_3jenkins-upgrade-2_121
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.