CVE-2018-1000864: Medium severity jenkins lts vulnerability
Published Dec 10, 2018
·Updated
A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.
Affected Software
5 affected componentsFixes available
maven/org.jenkins-ci.main:jenkins-core>=2.140<=2.153
2.154
maven/org.jenkins-ci.main:jenkins-core<=2.138.3
2.138.4
Jenkins Jenkins<=2.138.3
Jenkins Jenkins<=2.153
redhat OpenShift Container Platform=3.11
Event History
Dec 10, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 13, 2022
Advisory Published
01:48 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-1000864?
CVE-2018-1000864 is classified as a denial of service vulnerability.
2
How do I fix CVE-2018-1000864?
To fix CVE-2018-1000864, upgrade Jenkins to version 2.154 or later, or LTS 2.138.4 or later.
3
What versions are affected by CVE-2018-1000864?
CVE-2018-1000864 affects Jenkins versions 2.153 and earlier, and LTS 2.138.3 and earlier.
4
Who is vulnerable to CVE-2018-1000864?
Any attacker with Overall/Read permission in Jenkins can exploit CVE-2018-1000864.
5
What component of Jenkins is impacted by CVE-2018-1000864?
CVE-2018-1000864 affects the CronTab.java component in Jenkins.