CVE-2018-1999003 is an improper authorization vulnerability in Jenkins 2.132 and earlier, and 2.121.1 and earlier, specifically within the Queue.java component. This flaw allows authenticated attackers with Overall/Read permissions to cancel queued builds, impacting the integrity of the build process. The vulnerability has a CVSS score of 4.3 (Medium), indicating a low attack complexity and requiring low privileges, but with no confidentiality or availability impact beyond the ability to cancel builds. Its EPSS score is very low, suggesting a minimal likelihood of exploitation. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are also absent, indicating a lack of widespread attention or concern regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.121.1CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:* | ||
>= 2.122, <= 2.132CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:* | ||
1.9.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.