CVE-2018-1000420:
Improper authorization vulnerability in Jenkins Mesos Plugin
6.5
CVSS Score
3.0
Basic Information
CVE ID
GHSA ID
EPSS Score
0.44789%
CWE
Published
5/13/2022
Updated
1/30/2024
KEV Status
No
Technology
Java
Technical Details
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
---|---|---|---|
org.jenkins-ci.plugins:mesos | maven | <= 0.17.1 | 0.18 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability centers on unauthorized credential ID enumeration through missing permission checks in credential listing functionality. Jenkins plugins typically implement credential dropdown population via doFill[...]Items methods. The advisory explicitly states MesosCloud.java contained the vulnerability, and credential enumeration patterns in Jenkins consistently use methods named doFillCredentialIdItems for this purpose. The lack of ADMINISTER permission check in this method before returning credentials matches the described vulnerability mechanism.