First published: Tue Mar 13 2018(Updated: )
An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to modify the Gerrit configuration in Jenkins.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Gerrit Trigger | <=2.27.4 | |
maven/com.sonyericsson.hudson.plugins.gerrit:gerrit-trigger | <2.27.5 | 2.27.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000106 is classified as a medium severity vulnerability due to improper authorization allowing configuration modifications.
To fix CVE-2018-1000106, update the Jenkins Gerrit Trigger Plugin to version 2.27.5 or later.
CVE-2018-1000106 affects Jenkins Gerrit Trigger Plugin versions 2.27.4 and earlier.
CVE-2018-1000106 can facilitate unauthorized modification of the Gerrit configuration by users with Overall/Read access.
Yes, the vulnerability involves issues found in GerritManagement.java, GerritServer.java, and PluginImpl.java.