CVE-2018-1000197: High severity black duck hub vulnerability
Published Jun 5, 2018
·Updated
An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users with Overall/Read permission to read and write the Black Duck Hub plugin configuration.
Affected Software
2 affected componentsFixes available
maven/com.blackducksoftware.integration:blackduck-hub<=3.0.3
3.1.0
Jenkins Black Duck Hub Jenkins<=3.0.3
Event History
Jun 5, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
May 13, 2022
Advisory Published
via GitHub·01:48 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-1000197?
CVE-2018-1000197 has a medium severity level due to improper authorization permissions.
2
How do I fix CVE-2018-1000197?
To fix CVE-2018-1000197, upgrade the Jenkins Black Duck Hub Plugin to version 3.1.0 or later.
3
What systems are affected by CVE-2018-1000197?
CVE-2018-1000197 affects Jenkins Black Duck Hub Plugin version 3.0.3 and older.
4
What kind of vulnerability is CVE-2018-1000197?
CVE-2018-1000197 is an improper authorization vulnerability.
5
What can users do to protect themselves from CVE-2018-1000197?
Users should immediately update their Jenkins Black Duck Hub Plugin to the patched version to mitigate the risks associated with CVE-2018-1000197.