CVE-2018-6356
Estado: ModificadaMedia (6.5)—
Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not have access to. On Windows, any file accessible to the Jenkins master process could be downloaded. On other operating systems, any file within the Jenkins home directory accessible to the Jenkins master process could be downloaded.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.85%
- Percentil entre todas las CVEs puntuadas: 90
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-22
Referencias
- http://www.openwall.com/lists/oss-security/2018/02/14/1
- http://www.securityfocus.com/bid/103037
- https://jenkins.io/security/advisory/2018-02-14/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- http://www.openwall.com/lists/oss-security/2018/02/14/1
- http://www.securityfocus.com/bid/103037
- https://jenkins.io/security/advisory/2018-02-14/
- https://www.oracle.com/security-alerts/cpuapr2022.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-6356",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2018-02-20T15:29:00.367",
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2018/02/14/1",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/103037",
"tags": [
"Broken Link",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://jenkins.io/security/advisory/2018-02-14/",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.oracle.com/security-alerts/cpuapr2022.html",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2018/02/14/1",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/103037",
"tags": [
"Broken Link",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://jenkins.io/security/advisory/2018-02-14/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.oracle.com/security-alerts/cpuapr2022.html",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not have access to. On Windows, any file accessible to the Jenkins master process could be downloaded. On other operating systems, any file within the Jenkins home directory accessible to the Jenkins master process could be downloaded."
},
{
"lang": "es",
"value": "Jenkins, en versiones anteriores a la 2.107 y Jenkins LTS, en versiones anteriores a la 2.89.4, no evitaban correctamente la especificación de rutas relativas que escapaban un directorio base para las URL que acceden a archivos de recurso de los plugins. Esto permitía que los usuarios con permisos Overall/Read descarguen archivos del directorio maestro de Jenkins a los que no deberían tener acceso. En Windows, cualquier archivo accesible para el proceso Jenkins master podría ser descargado. En otros sistemas operativos, cualquier archivo en el directorio raíz de Jenkins accesible para su proceso maestro podría ser descargado."
}
],
"lastModified": "2026-06-17T02:01:43.860",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5489E08A-8EEC-4413-86EE-A3F5E764B80D",
"versionEndExcluding": "2.107"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "592ADCD0-BB96-4099-B70F-4DE102DB1828",
"versionEndExcluding": "2.89.4"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A4CA84D6-F312-4C29-A02B-050FCB7A902B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}