CVE-2018-1999047: Medium severity jenkins lts vulnerability
Published Aug 23, 2018
·Updated
A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.
Affected Software
2 affected components
Jenkins Jenkins<=2.121.2
Jenkins Jenkins<=2.137
Event History
Aug 23, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-1999047?
CVE-2018-1999047 has a medium severity level due to its potential impact on Jenkins system stability.
2
How do I fix CVE-2018-1999047?
To fix CVE-2018-1999047, upgrade Jenkins to version 2.138 or later.
3
Which versions of Jenkins are affected by CVE-2018-1999047?
Jenkins versions 2.137 and earlier, including 2.121.2 and earlier, are affected by CVE-2018-1999047.
4
What type of vulnerability is CVE-2018-1999047?
CVE-2018-1999047 is categorized as an improper authorization vulnerability that allows unauthorized actions.
5
Can an attacker exploit CVE-2018-1999047 remotely?
Yes, an attacker can remotely exploit CVE-2018-1999047 if they have access to the Jenkins Update Center.