CVE-2018-1999003: Medium severity jenkins lts vulnerability
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1999003?
CVE-2018-1999003 has a moderate severity rating, indicating it poses a significant risk but may not lead to immediate or severe impact.
How do I fix CVE-2018-1999003?
To remediate CVE-2018-1999003, upgrade Jenkins to version 2.133 or later, or to 2.121.2 if using the 2.121.x line.
Who is affected by CVE-2018-1999003?
CVE-2018-1999003 affects users of Jenkins version 2.132 and earlier, as well as 2.121.1 and earlier.
What types of attacks can CVE-2018-1999003 facilitate?
CVE-2018-1999003 can allow unauthorized users with Overall/Read permission to cancel queued builds, disrupting the CI/CD pipeline.
Is CVE-2018-1999003 related to other vulnerabilities?
CVE-2018-1999003 is similar to other Jenkins authorization vulnerabilities, emphasizing the importance of proper access controls.