Improper Authorization in Jenkins Gerrit Trigger Plugin
CVE-2018-1000106
5.4MEDIUM
Summary
An improper authorization vulnerability exists in the Jenkins Gerrit Trigger Plugin, specifically in the GerritManagement.java, GerritServer.java, and PluginImpl.java components. This flaw permits users with Overall/Read access to alter the configuration settings of Gerrit within Jenkins, potentially leading to unauthorized changes that compromise the integrity of the Jenkins environment.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability Reserved
Vulnerability published