Improper Authorization in Jenkins Mesos Plugin by CloudBees
CVE-2018-1000420
6.5MEDIUM
What is CVE-2018-1000420?
An improper authorization vulnerability has been identified in the Jenkins Mesos Plugin, particularly in the MesosCloud.java component. This flaw allows attackers with Overall/Read access to improperly access sensitive information, including credentials IDs for credentials stored within Jenkins. The vulnerability could lead to unauthorized disclosure of confidential data, emphasizing the need for secure configuration and access control measures. Users are advised to update to the latest version of the Mesos Plugin to mitigate these risks.