CVE-2016-4987
Jenkins Image Gallery Plugin allows Path Traversal
6.5
MEDIUM
CVSS 3.1
EPSS 0.36%
Description
Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbitrary directories and read arbitrary files via unspecified form fields.
How to fix CVE-2016-4987
To remediate CVE-2016-4987, upgrade the affected package to a fixed version below.
- Maven/com.tupilabs.image_gallery:image-gallery—upgrade to 1.4 or later
Is CVE-2016-4987 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |