cbcvebase.
CVE-2018-1000146
published 2018-04-05

CVE-2018-1000146: An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs…

high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute arbitrary code on the Jenkins master JVM.

Affected

12 ranges
VendorProductVersion rangeFixed in
jenkinsansible_plugin
jenkinsbuilds_started_before_the_plugin
jenkinscopy_to_slave_plugin
jenkinscucumber_living_documentation_plugin
jenkinsgithub_pull_request_builder_plugin
jenkinsliquibase_runner<= 1.3.0
jenkinsliquibase_runner_plugin
jenkinsmailer_plugin
jenkinsp4_plugin
jenkinsperforce_plugin
jenkinsreverse_proxy_auth_plugin
jenkinswe_recommend_that_users_of_perforce_plugin