Improper Authorization in Jenkins Gerrit Trigger Plugin
CVE-2018-1000106
5.4MEDIUM
What is CVE-2018-1000106?
An improper authorization vulnerability exists in the Jenkins Gerrit Trigger Plugin, specifically in the GerritManagement.java, GerritServer.java, and PluginImpl.java components. This flaw permits users with Overall/Read access to alter the configuration settings of Gerrit within Jenkins, potentially leading to unauthorized changes that compromise the integrity of the Jenkins environment.