High severity8.8NVD Advisory· Published Apr 5, 2018· Updated Jun 17, 2026
CVE-2018-1000146
CVE-2018-1000146
Description
An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute arbitrary code on the Jenkins master JVM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:liquibase-runnerMaven | < 1.4.3 | 1.4.3 |
Affected products
2- cpe:2.3:a:jenkins:liquibase_runner:*:*:*:*:*:jenkins:*:*Range: <=1.3.0
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-3hvc-xwjp-xr8mghsaADVISORY
- jenkins.io/security/advisory/2018-03-26/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-1000146ghsaADVISORY
- github.com/jenkinsci/liquibase-runner-plugin/commit/1817af0b5bb17e690d89c0a1623de8bd47f8c1a1ghsaWEB
- github.com/jenkinsci/liquibase-runner-plugin/commit/382a1ea84910db28a88089306b24d1e80818f0a5ghsaWEB
- github.com/jenkinsci/liquibase-runner-plugin/commit/7726ce4569a287e32fbda6f01ad2846ada909436ghsaWEB
News mentions
0No linked articles in our index yet.