First published: Mon Jul 23 2018(Updated: )
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress agent launches.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jenkins-ci.main:jenkins-core | >=2.122<2.132 | 2.132 |
maven/org.jenkins-ci.main:jenkins-core | <2.121.2 | 2.121.2 |
Jenkins LTS | <=2.121.1 | |
Jenkins LTS | >=2.122<=2.132 | |
Oracle Communications Cloud Native Core Automated Test Suite | =1.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1999004 has been classified as a critical vulnerability due to its potential impact on system integrity and control.
To remediate CVE-2018-1999004, upgrade Jenkins to versions 2.132 or later, or to 2.121.2 or later if using an earlier version.
Jenkins versions 2.132 and earlier, and versions 2.121.1 and earlier are affected by CVE-2018-1999004.
CVE-2018-1999004 is an improper authorization vulnerability that allows unauthorized users to initiate or abort agent launches.
Attackers with Overall/Read permission in Jenkins can exploit CVE-2018-1999004 to gain unauthorized control over agent management.