CVE-2018-1000148: Jenkins Copy To Slave

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

An exposure of sensitive information vulnerability exists in Jenkins Copy To Slave Plugin version 1.4.4 and older in CopyToSlaveBuildWrapper.java that allows attackers with permission to configure jobs to read arbitrary files from the Jenkins master file system.

Affected products

  • Jenkins Copy To Slave: up to and including 1.4.4

Published 2018-04-05. Last modified 2026-06-17.