CVE-2018-1000421: SSRF
Published Jan 9, 2019
·Updated
An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected Software
2 affected componentsFixes available
Apache Mesos Jenkins<=0.17.1
maven/org.jenkins-ci.plugins:mesos<=0.17.1
0.18
Event History
Jan 9, 2019
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·01:38 AM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-1000421.
2
What is the severity rating of CVE-2018-1000421?
CVE-2018-1000421 has a severity rating of 6.5 (Medium).
3
What software is affected by CVE-2018-1000421?
CVE-2018-1000421 affects Apache Mesos version 0.17.1 and earlier with Jenkins Mesos Plugin.
4
What is the CWE ID for this vulnerability?
The CWE ID for CVE-2018-1000421 is 918.
5
How can I fix CVE-2018-1000421?
To fix CVE-2018-1000421, update Jenkins Mesos Plugin to version 0.17.2 or later.