7.4
CVE-2018-1999035
- EPSS 0.04%
- Veröffentlicht 01.08.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:06
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A man in the middle vulnerability exists in Jenkins Inedo BuildMaster Plugin 1.3 and earlier in BuildMasterConfiguration.java, BuildMasterConfig.java, BuildMasterApi.java that allows attackers to impersonate any service that Jenkins connects to.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jenkins ≫ Inedo Buildmaster SwPlatformjenkins Version <= 1.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.096 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.4 | 2.2 | 5.2 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.