4.3
CVSSv3

CVE-2018-1000114

Published: 13/03/2018 Updated: 03/10/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and previous versions in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins promoted builds

Vendor Advisories

An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2311 and earlier in Statusjava and ManualConditionjava that allow an attacker with read access to jobs to perform promotions ...