PT-2018-9318 · Liquibase+1 · Liquibase Runner Plugin+1
Yoann Dubreuil
·
Published
2018-04-05
·
Updated
2022-05-13
·
CVE-2018-1000146
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Liquibase Runner Plugin versions 1.3.0 and older
Description
An arbitrary code execution issue exists that allows an attacker with permission to configure jobs to load and execute arbitrary code on the Jenkins master JVM.
Recommendations
For Liquibase Runner Plugin versions 1.3.0 and older, update to a version newer than 1.3.0 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Liquibase Runner Plugin