CVE-2018-1999001: Input Validation
A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attackers to provide crafted login credentials that cause Jenkins to move the config.xml file from the Jenkins home directory. If Jenkins is started without this file present, it will revert to the legacy defaults of granting administrator access to anonymous users.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1999001?
CVE-2018-1999001 has been assigned a medium severity rating due to its potential to allow unauthorized modification of configuration files in Jenkins.
How do I fix CVE-2018-1999001?
To fix CVE-2018-1999001, upgrade Jenkins to version 2.132 or higher, or to 2.121.2.
Which versions of Jenkins are affected by CVE-2018-1999001?
Jenkins versions 2.132 and earlier, as well as 2.121.1 and earlier, are affected by CVE-2018-1999001.
What type of vulnerability is CVE-2018-1999001?
CVE-2018-1999001 is classified as an unauthorized modification of configuration vulnerability.
Can CVE-2018-1999001 lead to data loss?
Yes, CVE-2018-1999001 could potentially lead to data loss by allowing attackers to manipulate the config.xml file.