CVE-2018-1000146
Summary
| CVE | CVE-2018-1000146 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-04-05 13:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute arbitrary code on the Jenkins master JVM. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jenkins | Liquibase Runner | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Jenkins Security Advisory 2018-03-26 | CONFIRM | jenkins.io | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 996882 Java (Maven) Security Update for org.jenkins-ci.plugins:liquibase-runner (GHSA-3hvc-xwjp-xr8m)