5.3
CVSSv3

CVE-2018-1000067

Published: 16/02/2018 Updated: 13/06/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An improper authorization vulnerability exists in Jenkins versions 2.106 and previous versions, and LTS 2.89.3 and previous versions, that allows an malicious user to have Jenkins submit HTTP GET requests and get limited information about the response.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins jenkins

oracle communications cloud native core automated test suite 1.9.0

Vendor Advisories

An improper authorization vulnerability exists in Jenkins versions 2106 and earlier, and LTS 2893 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response ...