← Back

CVE-2018-1999001

nvd nist
Published: Jul 23, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attackers to provide crafted login credentials that cause Jenkins to move the config.xml file from the Jenkins home directory. If Jenkins is started without this file present, it will revert to the legacy defaults of granting administrator access to anonymous users.

Affected (3)

1 product
Jenkins
1 product
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Jenkins
Up to 2.121.1
From 2.122 to 2.132
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.9.0

References (4)

Source: cve@mitre.org
MitigationVendor Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.