Medium severity4.3NVD Advisory· Published Mar 13, 2018· Updated Jun 17, 2026
CVE-2018-1000114
CVE-2018-1000114
Description
An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:promoted-buildsMaven | < 3.0 | 3.0 |
Affected products
2- cpe:2.3:a:jenkins:promoted_builds:*:*:*:*:*:jenkins:*:*Range: <=2.31.1
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-9rx5-w522-5fh7ghsaADVISORY
- jenkins.io/security/advisory/2018-02-26/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-1000114ghsaADVISORY
News mentions
0No linked articles in our index yet.