An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the Jenkins home directory is on a case-insensitive file system.
2018-02-16T00:29:01.887
2024-11-21T03:39:33.830
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jenkins | jenkins | ≤ 2.106 | Yes |
Application | jenkins | jenkins | ≤ 2.89.3 | Yes |
Application | oracle | communications_cloud_native_core_automated_test_suite | 1.9.0 | Yes |