First published: Thu Aug 23 2018(Updated: )
A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name when deserializing an instance of java.net.URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jenkins-ci.main:jenkins-core | >=2.122<2.138 | 2.138 |
maven/org.jenkins-ci.main:jenkins-core | <2.121.3 | 2.121.3 |
Jenkins LTS | <=2.121.2 | |
Jenkins LTS | <=2.137 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1999042 has been classified as a medium severity vulnerability.
To fix CVE-2018-1999042, upgrade to Jenkins version 2.138 or 2.121.3.
CVE-2018-1999042 is caused by the vulnerability in XStream2.java which allows domain name resolution during deserialization.
Jenkins versions 2.137 and earlier, as well as 2.121.2 and earlier, are affected by CVE-2018-1999042.
CVE-2018-1999042 is not limited to a specific plugin and affects the core Jenkins functionality.