CVE-2018-1000146: Jenkins Liquibase Runner
High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.
An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute arbitrary code on the Jenkins master JVM.
Affected products
- Jenkins Liquibase Runner: up to and including 1.3.0
Published 2018-04-05. Last modified 2026-06-17.