CVE-2018-1000114: Jenkins Promoted Builds
Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.
An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.
Affected products
- Jenkins Promoted Builds: up to and including 2.31.1
Published 2018-03-13. Last modified 2026-06-17.