First published: Thu Apr 05 2018(Updated: )
An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute arbitrary code on the Jenkins master JVM.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Liquibase Runner | <=1.3.0 | |
maven/org.jenkins-ci.plugins:liquibase-runner | <1.4.3 | 1.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000146 is considered a critical severity vulnerability due to its potential for arbitrary code execution.
To fix CVE-2018-1000146, upgrade the Liquibase Runner Plugin to version 1.4.3 or later.
CVE-2018-1000146 affects Jenkins installations with Liquibase Runner Plugin version 1.3.0 and older.
CVE-2018-1000146 allows attackers with sufficient permissions to execute arbitrary code on the Jenkins master JVM.
CVE-2018-1000146 was disclosed on March 26, 2018.