CVE-2018-1000114: Medium severity jenkins promoted builds vulnerability
Published Mar 13, 2018
·Updated
An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.
Affected Software
2 affected componentsFixes available
Jenkins Promoted Builds Jenkins<=2.31.1
maven/org.jenkins-ci.plugins:promoted-builds<=2.31.1
3.0
Event History
Mar 13, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
May 13, 2022
Advisory Published
via GitHub·01:48 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-1000114?
CVE-2018-1000114 is classified as a medium severity vulnerability.
2
What versions are affected by CVE-2018-1000114?
CVE-2018-1000114 affects Jenkins Promoted Builds Plugin versions 2.31.1 and earlier.
3
How do I fix CVE-2018-1000114?
To fix CVE-2018-1000114, upgrade the Jenkins Promoted Builds Plugin to version 3.0 or later.
4
What can attackers do with CVE-2018-1000114?
Attackers exploiting CVE-2018-1000114 can perform promotions on Jenkins jobs, even with read access.
5
Is there a workaround for CVE-2018-1000114?
There is no official workaround for CVE-2018-1000114; upgrading the plugin is the recommended action.