CVE-2018-1999001 Information
Feb 14, 2021
cve
Description
A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier 2.121.1 and earlier in User.java that allows attackers to provide crafted login credentials that cause Jenkins to move the config.xml file from the Jenkins home directory. If Jenkins is started without this file present it will revert to the legacy defaults of granting administrator access to anonymous users.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://jenkins.io/security/advisory/2018-07-18/SECURITY-897
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: