First published: Tue Mar 13 2018(Updated: )
An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Promoted Builds | <=2.31.1 | |
maven/org.jenkins-ci.plugins:promoted-builds | <=2.31.1 | 3.0 |
<=2.31.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000114 is classified as a medium severity vulnerability.
CVE-2018-1000114 affects Jenkins Promoted Builds Plugin versions 2.31.1 and earlier.
To fix CVE-2018-1000114, upgrade the Jenkins Promoted Builds Plugin to version 3.0 or later.
Attackers exploiting CVE-2018-1000114 can perform promotions on Jenkins jobs, even with read access.
There is no official workaround for CVE-2018-1000114; upgrading the plugin is the recommended action.