First published: Tue Mar 13 2018(Updated: )
An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in ``` OwnershipDescription.java, JobOwnerJobProperty.java, and OwnerNodeProperty.java ``` that allow an attacker with Job/Configure or Computer/Configure permission and without Ownership related permissions to override ownership metadata.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Job And Node Ownership | <=0.11.0 | |
maven/com.synopsys.jenkinsci:ownership | <0.12.0 | 0.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000107 is classified as a high severity vulnerability.
To fix CVE-2018-1000107, update the Jenkins Job and Node Ownership Plugin to version 0.12.0 or later.
CVE-2018-1000107 is caused by improper authorization in the Jenkins Job and Node Ownership Plugin.
Users of Jenkins with the Job and Node Ownership Plugin versions 0.11.0 and earlier are affected by CVE-2018-1000107.
An attacker with Job/Configure or Computer/Configure permission can exploit CVE-2018-1000107 to bypass ownership restrictions.