CVE-2018-1999042: Medium severity Jenkins Jenkins vulnerability
Published Aug 23, 2018
·Updated
A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name when deserializing an instance of java.net.URL.
Affected Software
4 affected componentsFixes available
maven/org.jenkins-ci.main:jenkins-core>=2.122<2.138
2.138
maven/org.jenkins-ci.main:jenkins-core<2.121.3
2.121.3
Jenkins Jenkins<=2.121.2
Jenkins Jenkins<=2.137
Event History
Aug 23, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
May 14, 2022
Advisory Published
01:04 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-1999042?
CVE-2018-1999042 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2018-1999042?
To fix CVE-2018-1999042, upgrade to Jenkins version 2.138 or 2.121.3.
3
What causes CVE-2018-1999042?
CVE-2018-1999042 is caused by the vulnerability in XStream2.java which allows domain name resolution during deserialization.
4
Which versions of Jenkins are affected by CVE-2018-1999042?
Jenkins versions 2.137 and earlier, as well as 2.121.2 and earlier, are affected by CVE-2018-1999042.
5
Is CVE-2018-1999042 only a threat if I'm using a specific plugin?
CVE-2018-1999042 is not limited to a specific plugin and affects the core Jenkins functionality.