Information disclosure - CVE-2018-6356
Published: March 1, 2018 / Updated: March 1, 2018
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information on the target system.
The vulnerability exists in the Extended Choice Parameter plug-in for Jenkins due to insufficient security restrictions. A remote attacker can use the Extended Choice Parameter plug-in, trigger path traversal and access potentially sensitive information.