cbcvebase.
CVE-2018-1000112
published 2018-03-13

CVE-2018-1000112: An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker with network…

medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker with network access to obtain a list of nodes and users.

Affected

20 ranges
VendorProductVersion rangeFixed in
jenkinsazure_slave_plugin
jenkinsazure_vm_agents_plugin
jenkinscoverity_plugin
jenkinscppncss_plugin
jenkinscredentials_plugin
jenkinsenvinject_plugin
jenkinsenvironment_injector_plugin
jenkinsgerrit_trigger_plugin
jenkinsgit_plugin
jenkinsgoogle_play_android_publisher_plugin
jenkinsids_in_google_play_android_publisher_plugin
jenkinsimproper_access_control_in_gerrit_trigger_plugin
jenkinsjob_and_node_ownership_plugin
jenkinsmercurial<= 2.2
jenkinsmercurial_plugin
jenkinstestlink_plugin
jenkinsurl_in_git_plugin
jenkinsurl_in_mercurial_plugin
jenkinsurl_in_subversion_plugin
jenkinsyou_have_ever_used_environment_injector_plugin