CVE-2018-1000107
13.03.2018, 13:29
An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in OwnershipDescription.java, JobOwnerJobProperty.java, and OwnerNodeProperty.java that allow an attacker with Job/Configure or Computer/Configure permission and without Ownership related permissions to override ownership metadata.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | job_and_node_ownership | 𝑥 ≤ 0.11.0 |
𝑥
= Vulnerable software versions