CVE-2018-1000110: Medium severity jenkins Git Jenkins vulnerability
Published Mar 13, 2018
·Updated
An improper authorization vulnerability exists in Jenkins Git Plugin version 3.7.0 and earlier in GitStatus.java that allows an attacker with network access to obtain a list of nodes and users.
Affected Software
1 affected component
jenkins Git Jenkins<=3.7.0
Event History
Mar 13, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-1000110?
The severity of CVE-2018-1000110 is classified as medium.
2
How do I fix CVE-2018-1000110?
To fix CVE-2018-1000110, upgrade Jenkins Git Plugin to version 3.8.0 or later.
3
What is CVE-2018-1000110 about?
CVE-2018-1000110 describes an improper authorization vulnerability in Jenkins Git Plugin that exposes a list of nodes and users.
4
What versions are affected by CVE-2018-1000110?
Jenkins Git Plugin version 3.7.0 and earlier are affected by CVE-2018-1000110.
5
Can CVE-2018-1000110 be exploited remotely?
Yes, CVE-2018-1000110 can be exploited by an attacker with network access.