Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1000152

Опубликовано: 05 апр. 2018
Источник: nvd
CVSS3: 6.3
CVSS2: 6.5
EPSS Низкий

Описание

An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSnapshot.java, Deploy.java, ExposeGuestInfo.java, FolderVSphereCloudProperty.java, PowerOff.java, PowerOn.java, Reconfigure.java, Rename.java, RenameSnapshot.java, RevertToSnapshot.java, SuspendVm.java, TakeSnapshot.java, VSphereBuildStepContainer.java, vSphereCloudProvisionedSlave.java, vSphereCloudSlave.java, vSphereCloudSlaveTemplate.java, VSphereConnectionConfig.java, vSphereStep.java that allows attackers to perform form validation related actions, including sending numerous requests to the configured vSphere server, potentially resulting in denial of service, or send credentials stored in Jenkins with known ID to an attacker-specified server ("test connection").

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jenkins:vsphere:*:*:*:*:*:jenkins:*:*
Версия до 2.16 (включая)

EPSS

Процентиль: 19%
0.00058
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.3
github
больше 3 лет назад

Jenkins vSphere Plugin incorrect authorization vulnerability

EPSS

Процентиль: 19%
0.00058
Низкий

6.3 Medium

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-863