CVE-2018-1000114

MEDIUM

Jenkins Promoted Builds Plugin <2.31.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 9.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-863
Status published
Products (2)
jenkins/promoted_builds < 2.31.1
org.jenkins-ci.plugins/promoted-builds 0 - 3.0Maven
Published Mar 13, 2018
Tracked Since Feb 18, 2026