CVE-2018-1000192: Medium severity jenkins lts vulnerability
A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000192?
CVE-2018-1000192 is rated as a medium severity vulnerability.
How do I fix CVE-2018-1000192?
To fix CVE-2018-1000192, upgrade Jenkins to version 2.121 or later for non-LTS or to LTS version 2.107.3 or later.
Who is affected by CVE-2018-1000192?
CVE-2018-1000192 affects users with Overall/Read access in Jenkins versions up to 2.120 and LTS versions up to 2.107.2.
What types of information can be exposed due to CVE-2018-1000192?
CVE-2018-1000192 allows the enumeration of all installed plugins, revealing their names and possibly their versions.
Is there a workaround for CVE-2018-1000192?
The best mitigation for CVE-2018-1000192 is to restrict access permissions to users who should not have Overall/Read access.