CVE-2018-1000420: Medium severity apache mesos vulnerability
Published Jan 9, 2019
·Updated
An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins.
Affected Software
2 affected componentsFixes available
Apache Mesos Jenkins<=0.17.1
maven/org.jenkins-ci.plugins:mesos<=0.17.1
0.18
Event History
Jan 9, 2019
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
May 13, 2022
Advisory Published
via GitHub·01:48 AM
Frequently Asked Questions
1
What is the vulnerability ID for this Jenkins Mesos Plugin vulnerability?
The vulnerability ID is CVE-2018-1000420.
2
What is the severity rating of CVE-2018-1000420?
The severity rating for CVE-2018-1000420 is medium, with a score of 6.5.
3
What is the description of CVE-2018-1000420?
CVE-2018-1000420 is an improper authorization vulnerability that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins.
4
What is the affected software version of CVE-2018-1000420?
The affected software version of CVE-2018-1000420 is Jenkins Mesos Plugin 0.17.1 and earlier.
5
How can I fix CVE-2018-1000420?
To fix CVE-2018-1000420, update to a version of Jenkins Mesos Plugin that is later than 0.17.1.