First published: Wed Aug 01 2018(Updated: )
A man in the middle vulnerability exists in Jenkins Inedo ProGet Plugin 0.8 and earlier in ProGetApi.java, ProGetConfig.java, ProGetConfiguration.java that allows attackers to impersonate any service that Jenkins connects to.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.inedo.proget:inedo-proget | <=0.8 | 1.0 |
Inedo ProGet | <=0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1999034 is classified as a medium severity vulnerability.
To fix CVE-2018-1999034, update the Inedo ProGet Plugin to version 1.0 or later.
CVE-2018-1999034 affects Jenkins Inedo ProGet Plugin versions up to and including 0.8.
The impact of CVE-2018-1999034 allows attackers to impersonate any service that Jenkins connects to.
Yes, a security advisory for CVE-2018-1999034 can be found on the Jenkins website.