CVE-2018-1000015 describes an authorization bypass vulnerability in Jenkins Pipeline: Nodes and Processes plugin versions 2.17 and earlier, specifically impacting instances using the Authorize Project plugin. This flaw allowed Pipeline 'node' blocks to execute on agents even when the associated build lacked the necessary Computer/Build permissions. Rated Medium severity (CVSS 4.8), the vulnerability requires high privileges and user interaction, with potential for limited confidentiality and integrity impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.17CPE matchmatch criteria | cpe:2.3:a:jenkins:pipeline_nodes_and_processes:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Incorrect permission checks in Pipeline: Nodes and Processes plugin
May 13, 2022jenkins-plugin-workflow-durable-task-step: Incorrect permission checks in Pipeline: Nodes and Processes plugin allows executing builds on agents while lacking Computer/Build permission (SECURITY-675)
Jan 22, 2018