CVE-2018-1000114

MEDIUM4.3EPSS 0.03%

Jenkins Promoted Builds Plugin allowed unauthorized users to run some promotion processes

發布日:2022/5/13修改日:2024/2/16

描述

An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.3CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

參考連結(2)