On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline `node` blocks on those agents due to incorrect permissions checks in Pipeline: Nodes and Processes plugin 2.17 and earlier.
References
Link | Resource |
---|---|
https://jenkins.io/security/advisory/2018-01-22/ | Vendor Advisory |
https://jenkins.io/security/advisory/2018-01-22/ | Vendor Advisory |
Configurations
History
21 Nov 2024, 03:39
Type | Values Removed | Values Added |
---|---|---|
References | () https://jenkins.io/security/advisory/2018-01-22/ - Vendor Advisory |
Information
Published : 2018-01-23 14:29
Updated : 2024-11-21 03:39
NVD link : CVE-2018-1000015
Mitre link : CVE-2018-1000015
CVE.ORG link : CVE-2018-1000015
JSON object : View
Products Affected
jenkins
- pipeline_nodes_and_processes
CWE
CWE-862
Missing Authorization