CVE-2018-1000169
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
5.3
MEDIUM
CVSS 3.1
EPSS 0.18%
Description
An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in CLICommand.java and ViewOptionHandler.java that allows unauthorized attackers to confirm the existence of agents or views with an attacker-specified name by sending a CLI command to Jenkins.
How to fix CVE-2018-1000169
To remediate CVE-2018-1000169, upgrade the affected package to a fixed version below.
- —upgrade to 2.107.2 or later
Is CVE-2018-1000169 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.107.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |