An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3446 | An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions. |
Github GHSA |
GHSA-9rx5-w522-5fh7 | Jenkins Promoted Builds Plugin allowed unauthorized users to run some promotion processes |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T23:16:12.603Z
Reserved: 2018-03-13T00:00:00Z
Link: CVE-2018-1000114
No data.
Status : Modified
Published: 2018-03-13T13:29:00.843
Modified: 2024-11-21T03:39:40.520
Link: CVE-2018-1000114
OpenCVE Enrichment
No data.
EUVD
Github GHSA