CVE-2018-1000114
published 2018-03-13CVE-2018-1000114: An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an…
PriorityP421medium4.3CVSS 3.0
AVNACLPRLUINSUCNILAN
EPSS
0.64%
46.5th percentile
An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | azure_slave_plugin | — | — |
| jenkins | azure_vm_agents_plugin | — | — |
| jenkins | coverity_plugin | — | — |
| jenkins | cppncss_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | envinject_plugin | — | — |
| jenkins | environment_injector_plugin | — | — |
| jenkins | gerrit_trigger_plugin | — | — |
| jenkins | git_plugin | — | — |
| jenkins | google_play_android_publisher_plugin | — | — |
| jenkins | ids_in_google_play_android_publisher_plugin | — | — |
| jenkins | improper_access_control_in_gerrit_trigger_plugin | — | — |
| jenkins | job_and_node_ownership_plugin | — | — |
| jenkins | mercurial_plugin | — | — |
| jenkins | promoted_builds | <= 2.31.1 | — |
| jenkins | testlink_plugin | — | — |
| jenkins | url_in_git_plugin | — | — |
| jenkins | url_in_mercurial_plugin | — | — |
| jenkins | url_in_subversion_plugin | — | — |
| jenkins | you_have_ever_used_environment_injector_plugin | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Jenkins Promoted Builds Plugin allowed unauthorized users to run some promotion processes
ghsa·2022-05-13
CVE-2018-1000114 [MEDIUM] CWE-863 Jenkins Promoted Builds Plugin allowed unauthorized users to run some promotion processes
Jenkins Promoted Builds Plugin allowed unauthorized users to run some promotion processes
An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.
OSV
Jenkins Promoted Builds Plugin allowed unauthorized users to run some promotion processes
osv·2022-05-13
CVE-2018-1000114 [MEDIUM] Jenkins Promoted Builds Plugin allowed unauthorized users to run some promotion processes
Jenkins Promoted Builds Plugin allowed unauthorized users to run some promotion processes
An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.
Red Hat
jenkins-plugin-promoted-builds: Promoted Builds Plugin allowed unauthorized users to run some promotion processes (SECURITY-746)
vendor_redhat·2018-02-26·CVSS 4.3
CVE-2018-1000114 [MEDIUM] CWE-863 jenkins-plugin-promoted-builds: Promoted Builds Plugin allowed unauthorized users to run some promotion processes (SECURITY-746)
jenkins-plugin-promoted-builds: Promoted Builds Plugin allowed unauthorized users to run some promotion processes (SECURITY-746)
An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.
Package: jenkins-plugin-promoted-builds (Red Hat OpenShift Enterprise 3) - Affected
Jenkins
Jenkins Security Advisory 2018-02-26
vendor_jenkins·2018-02-26
CVE-2015-5262 [MEDIUM] Jenkins Security Advisory 2018-02-26
Title: Jenkins Security Advisory 2018-02-26
Jenkins Security Advisory 2018-02-26
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
Azure Slave
Plugin
Coverity
Plugin
CppNCSS
Plugin
Environment Injector
Plugin
Gerrit Trigger
Plugin
Git
Plugin
Google Play Android Publisher
Plugin
Job and Node o
No detection rules found.
No public exploits indexed.
2018-03-13
Published