CVE-2018-1000175 – org.jenkins-ci.plugins:htmlpublisher
Package
Manager: maven
Name: org.jenkins-ci.plugins:htmlpublisher
Vulnerable Version: >=0 <1.16
Severity
Level: Medium
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00342 pctl0.56182
Details
Jenkins HTML Publisher Plugin path traversal vulnerability A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build step to override arbitrary files on the Jenkins master. In version 1.16, non-alphanumeric characters in report names are escaped for use as part of a URL and as a directory name.
Metadata
Created: 2022-05-14T03:18:39Z
Modified: 2022-12-12T16:55:41Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4x63-3p7q-xmh7/GHSA-4x63-3p7q-xmh7.json
CWE IDs: ["CWE-22"]
Alternative ID: GHSA-4x63-3p7q-xmh7
Finding: F063
Auto approve: 1