← Vulnerability feed

Vulnerability record · CVE-2018-1999002 · published 23 July 2018

CVE-2018-1999002: Jenkins Stapler framework arbitrary file read

Jenkins · Jenkins

Jenkins 2.132 and earlier, and 2.121.1 and earlier, contain an arbitrary file read flaw in the Stapler web framework (org/kohsuke/stapler/Stapler.java). Crafted HTTP requests can return the contents of any file on the Jenkins master that the master process can access. This exposes credentials, keys and configuration on the controller, which is a high-value target.

7.5 CVSS 3.1 High EPSS 87% · top 0.3%
7.5CVSS 3.1 base score, v2 5.0
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the Jenkins master file system that the Jenkins master has access to.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated network file read on a Jenkins master with a public exploit and very high EPSS, though not in KEV.

What it is

Jenkins 2.132 and earlier, and 2.121.1 and earlier, contain an arbitrary file read flaw in the Stapler web framework (org/kohsuke/stapler/Stapler.java). Crafted HTTP requests can return the contents of any file on the Jenkins master that the master process can access. This exposes credentials, keys and configuration on the controller, which is a high-value target.

Impact

An unauthenticated attacker can read arbitrary files on the Jenkins master, including secrets, credentials and configuration data. That access can enable further compromise of the Jenkins instance and connected systems.

Attack surface

Reachable over the network via crafted HTTP requests to the Jenkins master; the CVSS vector shows no privileges or user interaction required. No authentication is needed per the vector.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.86641, 99.7th percentile) and a public Exploit-DB entry (46453) exists, indicating mature public exploitation.

What to do

  • Upgrade Jenkins to a version after 2.132 (or after 2.121.1 on the LTS line) per the vendor advisory SECURITY-914.
  • If immediate upgrade is not possible, apply the mitigations in the Jenkins 2018-07-18 advisory and restrict network access to the Jenkins master.
  • Apply the Oracle CPU April 2022 patch for affected Oracle products bundling Jenkins.
  • Run Jenkins behind an authenticating reverse proxy and limit exposure to trusted networks only.
  • Rotate any credentials, keys or tokens that may have been readable on the master.

Detection

  • Review Jenkins access logs for unusual HTTP requests targeting Stapler endpoints or file paths.
  • Monitor for outbound or anomalous reads of sensitive files by the Jenkins process.
  • Use the public Exploit-DB PoC (46453) to test and confirm exposure in a controlled environment.
  • Alert on Jenkins versions at or below 2.132 / 2.121.1 still present in the environment.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-1999002 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-23897Jenkins CLI parser arbitrary file read via @ path expansionJenkins 2.441 and earlier, and LTS 2.426.2 and earlier, fails to disable a CLI command parser feature that replaces an '@' character followed by a fi…KEVEPSS 100%analysed9.8CVE-2022-22963Spring Cloud Function routing expression SpEL injection RCESpring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression w…KEVEPSS 100%analysed9.8CVE-2022-22965Spring Framework data binding remote code execution (Spring4Shell)Spring MVC and Spring WebFlux applications on JDK 9+ can be exploited through data binding to achieve remote code execution. The known exploit path r…KEVEPSS 100%analysed9.8CVE-2018-1000861Jenkins Stapler framework URL routing allows remote code executionThe Stapler web framework in Jenkins 2.153 and earlier and LTS 2.138.3 and earlier lets attackers invoke unintended Java methods by requesting crafte…KEVEPSS 98%analysed9.8CVE-2017-1000353Jenkins CLI Java deserialization allows unauthenticated remote code executionJenkins 2.56 and earlier, and 2.46.1 LTS and earlier, deserialize attacker-supplied Java SignedObject data sent to the Jenkins CLI, bypassing the exi…KEVEPSS 100%analysed8.5CVE-2021-39144XStream deserialization allows remote command executionXStream, a Java library that serializes objects to and from XML, can execute host commands when a remote attacker with sufficient rights manipulates …KEVEPSS 98%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2015-5317Jenkins Fingerprints pages expose job and build namesJenkins before 1.638 and LTS before 1.625.2 expose sensitive job and build name information through the Fingerprints pages when requested directly. T…KEVEPSS 23%analysed

Source: NIST National Vulnerability Database (record CVE-2018-1999002), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.