First published: Wed Aug 01 2018(Updated: )
A man in the middle vulnerability exists in Jenkins Inedo BuildMaster Plugin 1.3 and earlier in BuildMasterConfiguration.java, BuildMasterConfig.java, BuildMasterApi.java that allows attackers to impersonate any service that Jenkins connects to.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Inedo Buildmaster | <=1.3 | |
maven/com.inedo.buildmaster:inedo-buildmaster | <=1.3 | 2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1999035 has a medium severity rating due to its potential for man-in-the-middle attacks.
To fix CVE-2018-1999035, upgrade the Jenkins Inedo BuildMaster Plugin to version 2.0 or later.
CVE-2018-1999035 affects Jenkins Inedo BuildMaster Plugin versions 1.3 and earlier.
CVE-2018-1999035 is classified as a man-in-the-middle vulnerability.
Any attacker with the ability to intercept communications between Jenkins and service endpoints can exploit CVE-2018-1999035.