cbcvebase.
CVE-2018-1000110
published 2018-03-13

CVE-2018-1000110: An improper authorization vulnerability exists in Jenkins Git Plugin version 3.7.0 and earlier in GitStatus.java that allows an attacker with network access to…

medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
An improper authorization vulnerability exists in Jenkins Git Plugin version 3.7.0 and earlier in GitStatus.java that allows an attacker with network access to obtain a list of nodes and users.

Affected

23 ranges
VendorProductVersion rangeFixed in
jenkinsazure_slave_plugin
jenkinsazure_vm_agents_plugin
jenkinscoverity_plugin
jenkinscppncss_plugin
jenkinscredentials_plugin
jenkinsenvinject_plugin
jenkinsenvironment_injector_plugin
jenkinsgerrit_trigger_plugin
jenkinsgit<= 3.7.0
jenkinsgit_plugin
jenkinsgoogle_play_android_publisher_plugin
jenkinsids_in_google_play_android_publisher_plugin
jenkinsimproper_access_control_in_gerrit_trigger_plugin
jenkinsjob_and_node_ownership_plugin
jenkinsmercurial_plugin
jenkinstestlink_plugin
jenkinsurl_in_git_plugin
jenkinsurl_in_mercurial_plugin
jenkinsurl_in_subversion_plugin
jenkinsyou_have_ever_used_environment_injector_plugin
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_git_2.23.4-1_on_cbl_mariner_1.0