MEDIUM
jenkins: Missing permission check allows users with Overall/Read permission to initiate agent launches
Published Jul 23, 2018
4.3
MEDIUMCVSS 3.1
EPSS 0.94%
Description
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress agent launches.
Affected products
No data.
No data.
Red Hat OpenShift Enterprise 3
jenkins
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Enterprise 3 | jenkins | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (9)
- https://access.redhat.com/security/cve/CVE-2018-1999004 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1609617 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5603 Advisory
- https://github.com/advisories/GHSA-wmr8-25ff-ggpj Advisory
- https://github.com/jenkinsci/jenkins/commit/40250f08aca7f3f8816f21870ee23463a52ef2f2
- https://jenkins.io/security/advisory/2018-07-18/#SECURITY-892 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1999004
- https://www.cve.org/CVERecord?id=CVE-2018-1999004
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-1999004 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1609617 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5603 | Advisory | |
| https://github.com/advisories/GHSA-wmr8-25ff-ggpj | Advisory | |
| https://github.com/jenkinsci/jenkins/commit/40250f08aca7f3f8816f21870ee23463a52ef2f2 | ||
| https://jenkins.io/security/advisory/2018-07-18/#SECURITY-892 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1999004 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1999004 | ||
| https://www.oracle.com/security-alerts/cpuapr2022.html | x_refsource_MISCPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 23, 2018
Updated Aug 5, 2024
Reserved Jul 18, 2018
Link CVE-2018-1999004
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-5603 GHSA-WMR8-25FF-GGPJ Assigner mitre
Published Jul 23, 2018
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2022-5603