CVE-2018-1000189 | Maximal damage | 8.8 |
Easy to exploit |
(other affected products) | Published: Tue Jun 5 20:29:00 2018 UTC. Last Modified: Thu Oct 3 00:03:00 2019 UTC |
CPE matches: cpe:2.3:a:jenkins:absint_astree:*:*:*:*:*:jenkins:*:* && versionEndIncluding=1.0.5
Description
A command execution vulnerability exists in Jenkins Absint Astree Plugin 1.0.5 and older in AstreeBuilder.java that allows attackers with Overall/Read access to execute a command on the Jenkins master.
Damage
- Complete loss of protection.
- Access to all information.
- Full Denial Of Service (DoS).
Attack conditions
- Remote attacking is possible through the network but requires the attacker to have regular user privileges.
- No user interaction is required.
- The attack is estimated to have a high success rate, once attempted.
Damage and attack conditions obtained from CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (CVSSv3)