ZeroHour

CVE-2018-1999038

CVSS 3.0
4.2 medium
EPSS
<1%p40
Published
()
Modified
Description

A confused deputy vulnerability exists in Jenkins Publisher Over CIFS Plugin 0.10 and earlier in CifsPublisherPluginDescriptor.java that allows attackers to have Jenkins connect to an attacker specified CIFS server with attacker specified credentials.

Vendors
jenkins
Products
publish over cifs
Weakness
CWE-441
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.