Arbitrary File Override Vulnerability in Jenkins HTML Publisher Plugin

Arbitrary File Override Vulnerability in Jenkins HTML Publisher Plugin

CVE-2018-1000175 · MEDIUM Severity

AV:N/AC:L/AU:S/C:N/I:P/A:N

A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build step to override arbitrary files on the Jenkins master.

Learn more about our Web Application Penetration Testing UK.