jenkins: Unauthorized users could cancel scheduled restarts initiated from the update center
Published Aug 23, 2018
6.5
MEDIUMCVSS 3.0
EPSS 0.77%
Description
A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.
Affected products
No data.
No data.
Red Hat OpenShift Container Platform 3.10
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.11
jenkins
Not affected
Red Hat OpenShift Container Platform 3.2
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.3
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.4
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.5
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.6
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.7
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.9
jenkins
Will not fix
Red Hat OpenShift Enterprise 3.1
jenkins
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.10 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.11 | jenkins | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.2 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.3 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.4 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.5 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.6 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.7 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.9 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Enterprise 3.1 | jenkins | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2018-1999047 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1620354 Issue Tracking
- https://github.com/advisories/GHSA-r2jf-rc5v-vmpv Advisory
- https://jenkins.io/security/advisory/2018-08-15/#SECURITY-1076 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1999047
- https://www.cve.org/CVERecord?id=CVE-2018-1999047
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-1999047 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1620354 | Issue Tracking | |
| https://github.com/advisories/GHSA-r2jf-rc5v-vmpv | Advisory | |
| https://jenkins.io/security/advisory/2018-08-15/#SECURITY-1076 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1999047 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1999047 |
Change history (0)
No recorded changes yet.