Medium severity4.8NVD Advisory· Published Jan 23, 2018· Updated Jun 17, 2026
CVE-2018-1000015
CVE-2018-1000015
Description
On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline node blocks on those agents due to incorrect permissions checks in Pipeline: Nodes and Processes plugin 2.17 and earlier.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins.workflow:workflow-durable-task-stepMaven | < 2.18 | 2.18 |
Affected products
2- cpe:2.3:a:jenkins:pipeline_nodes_and_processes:*:*:*:*:*:jenkins:*:*Range: <=2.17
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-9r7f-rqhw-j8h8ghsaADVISORY
- jenkins.io/security/advisory/2018-01-22/nvdVendor Advisory
- nvd.nist.gov/vuln/detail/CVE-2018-1000015ghsaADVISORY
- jenkins.io/security/advisory/2018-01-22ghsaWEB
News mentions
0No linked articles in our index yet.