Jenkins CVE-2018-1000169 Information Disclosure Vulnerability
BID:104351
Info
Jenkins CVE-2018-1000169 Information Disclosure Vulnerability
| Bugtraq ID: | 104351 |
| Class: | Design Error |
| CVE: |
CVE-2018-1000169 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2018 12:00AM |
| Updated: | Apr 11 2018 12:00AM |
| Credit: | Assaf Berg |
| Vulnerable: |
Jenkins-Ci Jenkins LTS 1.652.2 Jenkins-Ci Jenkins LTS 1.651.2 Jenkins-Ci Jenkins LTS 1.651.1 Jenkins-Ci Jenkins LTS 1.642.2 Jenkins-Ci Jenkins LTS 1.642.1 Jenkins-Ci Jenkins LTS 1.625.3 Jenkins-Ci Jenkins LTS 1.625.2 Jenkins-Ci Jenkins LTS 1.625.1 Jenkins-Ci Jenkins LTS 1.609.1 Jenkins-Ci Jenkins LTS 1.580.1 Jenkins-Ci Jenkins LTS 1.565.3 Jenkins-Ci Jenkins LTS 2.107.1 Jenkins-Ci Jenkins 1.480.3 Jenkins-Ci Jenkins 1.480.2 Jenkins-Ci Jenkins 1.480.1 Jenkins-Ci Jenkins 1.409.3 Jenkins-Ci Jenkins 1.7.24 Jenkins-Ci Jenkins 2.115 Jenkins-Ci Jenkins 2.107 Jenkins-Ci Jenkins 2.106 Jenkins-Ci Jenkins 2.1 Jenkins-Ci Jenkins 2.0 Jenkins-Ci Jenkins 1.7.24.1 Jenkins-Ci Jenkins 1.656 Jenkins-Ci Jenkins 1.655 Jenkins-Ci Jenkins 1.654 Jenkins-Ci Jenkins 1.653 Jenkins-Ci Jenkins 1.652 Jenkins-Ci Jenkins 1.651 Jenkins-Ci Jenkins 1.650 Jenkins-Ci Jenkins 1.649 Jenkins-Ci Jenkins 1.641 Jenkins-Ci Jenkins 1.640 Jenkins-Ci Jenkins 1.638 Jenkins-Ci Jenkins 1.637 Jenkins-Ci Jenkins 1.600 Jenkins-Ci Jenkins 1.587 Jenkins-Ci Jenkins 1.578 Jenkins-Ci Jenkins 1.565.3-3 Jenkins-Ci Jenkins 1.551 Jenkins-Ci Jenkins 1.550 Jenkins-Ci Jenkins 1.532.2 Jenkins-Ci Jenkins 1.532.1 Jenkins-Ci Jenkins 1.523 Jenkins-Ci Jenkins 1.514 Jenkins-Ci Jenkins 1.513 Jenkins-Ci Jenkins 1.509.1 Jenkins-Ci Jenkins 1.509 Jenkins-Ci Jenkins 1.502 Jenkins-Ci Jenkins 1.497 Jenkins-Ci Jenkins 1.491 Jenkins-Ci Jenkins 1.482 Jenkins-Ci Jenkins 1.466.2 LTS Jenkins-Ci Jenkins 1.454 Jenkins-Ci Jenkins 1.452 Jenkins-Ci Jenkins 1.451 Jenkins-Ci Jenkins 1.447 Jenkins-Ci Jenkins 1.446 Jenkins-Ci Jenkins 1.438 Jenkins-Ci Jenkins 1.424.5.1 Jenkins-Ci Jenkins 1.424.5 Jenkins-Ci Jenkins 1.424.3 Jenkins-Ci Jenkins 1.424.2 Jenkins-Ci Jenkins 1.424.1 Jenkins-Ci Jenkins 1.408 Jenkins-Ci Jenkins 1.400.0.13 Jenkins-Ci Jenkins 1.400.0.12 |
| Not Vulnerable: |
Jenkins-Ci Jenkins LTS 2.107.2 Jenkins-Ci Jenkins 2.116 |
Discussion
Jenkins CVE-2018-1000169 Information Disclosure Vulnerability
Jenkins is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks.
The following versions are affected:
Jenkins 2.115 and prior versions.
Jenkins LTS 2.107.1 and prior versions.
Jenkins is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks.
The following versions are affected:
Jenkins 2.115 and prior versions.
Jenkins LTS 2.107.1 and prior versions.
References
Jenkins CVE-2018-1000169 Information Disclosure Vulnerability
References:
References:
- Jenkins CI Homepage (Jenkins CI)
- Jenkins Security Advisory 2018-04-11 (Jenkins CI)