ZeroHour

CVE-2018-1000114

CVSS 3.0
4.3 medium
EPSS
<1%p48
Published
()
Modified
Description

An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.

Vendors
jenkins
Products
promoted builds
Weakness
CWE-863
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.