Vulnerability record · CVE-2018-1999002 · published 23 July 2018
CVE-2018-1999002: Jenkins Stapler framework arbitrary file read
Jenkins · Jenkins
Jenkins 2.132 and earlier, and 2.121.1 and earlier, contain an arbitrary file read flaw in the Stapler web framework (org/kohsuke/stapler/Stapler.java). Crafted HTTP requests can return the contents of any file on the Jenkins master that the master process can access. This exposes credentials, keys and configuration on the controller, which is a high-value target.
Description
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the Jenkins master file system that the Jenkins master has access to.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network file read on a Jenkins master with a public exploit and very high EPSS, though not in KEV.
What it is
Jenkins 2.132 and earlier, and 2.121.1 and earlier, contain an arbitrary file read flaw in the Stapler web framework (org/kohsuke/stapler/Stapler.java). Crafted HTTP requests can return the contents of any file on the Jenkins master that the master process can access. This exposes credentials, keys and configuration on the controller, which is a high-value target.
Impact
An unauthenticated attacker can read arbitrary files on the Jenkins master, including secrets, credentials and configuration data. That access can enable further compromise of the Jenkins instance and connected systems.
Attack surface
Reachable over the network via crafted HTTP requests to the Jenkins master; the CVSS vector shows no privileges or user interaction required. No authentication is needed per the vector.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.86641, 99.7th percentile) and a public Exploit-DB entry (46453) exists, indicating mature public exploitation.
What to do
- Upgrade Jenkins to a version after 2.132 (or after 2.121.1 on the LTS line) per the vendor advisory SECURITY-914.
- If immediate upgrade is not possible, apply the mitigations in the Jenkins 2018-07-18 advisory and restrict network access to the Jenkins master.
- Apply the Oracle CPU April 2022 patch for affected Oracle products bundling Jenkins.
- Run Jenkins behind an authenticating reverse proxy and limit exposure to trusted networks only.
- Rotate any credentials, keys or tokens that may have been readable on the master.
Detection
- Review Jenkins access logs for unusual HTTP requests targeting Stapler endpoints or file paths.
- Monitor for outbound or anomalous reads of sensitive files by the Jenkins process.
- Use the public Exploit-DB PoC (46453) to test and confirm exposure in a controlled environment.
- Alert on Jenkins versions at or below 2.132 / 2.121.1 still present in the environment.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jenkins.io/security/advisory/2018-07-18/#SECURITY-914 | MitigationVendor Advisory |
| https://www.exploit-db.com/exploits/46453/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
| https://jenkins.io/security/advisory/2018-07-18/#SECURITY-914 | MitigationVendor Advisory |
| https://www.exploit-db.com/exploits/46453/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.oracle.com/security-alerts/cpuapr2022.html | PatchThird Party Advisory |
Track CVE-2018-1999002 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1999002), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.