Improper Authorization in Jenkins Gerrit Trigger Plugin
CVE-2018-1000106

5.4MEDIUM

Key Information:

Vendor
Jenkins
Vendor
CVE Published:
13 March 2018

Summary

An improper authorization vulnerability exists in the Jenkins Gerrit Trigger Plugin, specifically in the GerritManagement.java, GerritServer.java, and PluginImpl.java components. This flaw permits users with Overall/Read access to alter the configuration settings of Gerrit within Jenkins, potentially leading to unauthorized changes that compromise the integrity of the Jenkins environment.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.