First published: Tue Mar 13 2018(Updated: )
An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to retrieve some configuration information about Gerrit in Jenkins.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Gerrit Trigger | <=2.27.4 | |
maven/com.sonyericsson.hudson.plugins.gerrit:gerrit-trigger | <2.27.5 | 2.27.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000105 is classified as a medium severity vulnerability.
CVE-2018-1000105 is caused by improper authorization in the Jenkins Gerrit Trigger Plugin, allowing access to configuration information.
To fix CVE-2018-1000105, upgrade the Jenkins Gerrit Trigger Plugin to version 2.27.5 or later.
Users of Jenkins Gerrit Trigger Plugin versions 2.27.4 and earlier are affected by CVE-2018-1000105.
CVE-2018-1000105 can allow attackers with Overall/Read access to retrieve configuration details about Gerrit in Jenkins.