cbcvebase.
CVE-2018-1000114
published 2018-03-13

CVE-2018-1000114: An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an…

medium4.3CVSS 3.0
AVNACLPRLUINSUCNILAN
An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.

Affected

20 ranges
VendorProductVersion rangeFixed in
jenkinsazure_slave_plugin
jenkinsazure_vm_agents_plugin
jenkinscoverity_plugin
jenkinscppncss_plugin
jenkinscredentials_plugin
jenkinsenvinject_plugin
jenkinsenvironment_injector_plugin
jenkinsgerrit_trigger_plugin
jenkinsgit_plugin
jenkinsgoogle_play_android_publisher_plugin
jenkinsids_in_google_play_android_publisher_plugin
jenkinsimproper_access_control_in_gerrit_trigger_plugin
jenkinsjob_and_node_ownership_plugin
jenkinsmercurial_plugin
jenkinspromoted_builds<= 2.31.1
jenkinstestlink_plugin
jenkinsurl_in_git_plugin
jenkinsurl_in_mercurial_plugin
jenkinsurl_in_subversion_plugin
jenkinsyou_have_ever_used_environment_injector_plugin