CVE-2018-1999038

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/08/2018
Last modified:
15/10/2018

Description

A confused deputy vulnerability exists in Jenkins Publisher Over CIFS Plugin 0.10 and earlier in CifsPublisherPluginDescriptor.java that allows attackers to have Jenkins connect to an attacker specified CIFS server with attacker specified credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:publish_over_cifs:*:*:*:*:*:jenkins:*:* 0.10 (including)


References to Advisories, Solutions, and Tools