CVE-2018-1000067

Description

An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.353

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Jenkins 2.89.3Windows
Vulnerabilities CVE-2018-1000067,CVE-2018-1000068,CVE-2018-6356 are fixed in Jenkins-Core 2.89.4Windows
Vulnerabilities CVE-2018-1000067,CVE-2018-1000068,CVE-2018-6356 are fixed in Jenkins-Core 2.107Windows
Multiple vulnerabilities affected in Jenkins 2.89.3 (For Ubuntu)Linux
Multiple vulnerabilities affected in Jenkins 2.89.3 (For Debian)Linux
Multiple vulnerabilities affected in Jenkins 2.89.3 (For Centos)Linux
Multiple vulnerabilities affected in Jenkins 2.89.3 (For RedHat)Linux
Multiple vulnerabilities affected in Jenkins 2.89.3 (For Suse)Linux
Vulnerabilities CVE-2018-1000067,CVE-2018-1000068,CVE-2018-6356 are fixed in Jenkins-Core for Linux 2.89.4Linux
Vulnerabilities CVE-2018-1000067,CVE-2018-1000068,CVE-2018-6356 are fixed in Jenkins-Core for Linux 2.107Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234