Vulnerability Description
An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in OwnershipDescription.java, JobOwnerJobProperty.java, and OwnerNodeProperty.java that allow an attacker with Job/Configure or Computer/Configure permission and without Ownership related permissions to override ownership metadata.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Job And Node Ownership | <= 0.11.0 |
Related Weaknesses (CWE)
References
- https://jenkins.io/security/advisory/2018-02-26/#SECURITY-498Vendor Advisory
- https://jenkins.io/security/advisory/2018-02-26/#SECURITY-498Vendor Advisory
FAQ
What is CVE-2018-1000107?
CVE-2018-1000107 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in OwnershipDescription.java, JobOwnerJobProperty.java, and OwnerNodeProperty.java that allow...
How severe is CVE-2018-1000107?
CVE-2018-1000107 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1000107?
Check the references section above for vendor advisories and patch information. Affected products include: Jenkins Job And Node Ownership.