PT-2018-9318 · Liquibase+1 · Liquibase Runner Plugin+1
Yoann Dubreuil
·
Publicado
2018-04-05
·
Atualizado
2022-05-13
·
CVE-2018-1000146
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Liquibase Runner Plugin versions 1.3.0 and older
Description
An arbitrary code execution issue exists that allows an attacker with permission to configure jobs to load and execute arbitrary code on the Jenkins master JVM.
Recommendations
For Liquibase Runner Plugin versions 1.3.0 and older, update to a version newer than 1.3.0 to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Jenkins
Liquibase Runner Plugin