VulnerabilityModified
CVE-2018-1000067
An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.
MEDIUM 5.3EPSS 1.67%
Does this matter?
Lower severity and a low EPSS score (1.67%). Track it; it rarely justifies an emergency change on its own.
Description
An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.67% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- jenkins/jenkins · oracle/communications cloud native core automated test suite
- Source
- cve@mitre.org
References
- https://jenkins.io/security/advisory/2018-02-14/#SECURITY-506Vendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://jenkins.io/security/advisory/2018-02-14/#SECURITY-506Vendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.