cvedb.io
CVE-2018-1000607
MEDIUM · CVSS 6.5
EPSS exploitation probability: 0%
Published 2018-06-26T17:29:00.570 · Last modified 2026-06-17T01:32:55.653

Summary

A arbitrary file write vulnerability exists in Jenkins Fortify CloudScan Plugin 1.5.1 and earlier in ArchiveUtil.java that allows attackers able to control rulepack zip file contents to overwrite any file on the Jenkins master file system, only limited by the permissions of the user the Jenkins master process is running as.

Affected products

jenkins — fortify_cloudscan

Does this affect you?

Add your gear to cvedb and we'll alert you only when jenkins ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.