CVE-2017-1000087
published 2017-10-05CVE-2017-1000087: GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use. This functionality did…
PriorityP420medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
0.79%
51.9th percentile
GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those could be used as part of an attack to capture the credentials using another vulnerability.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | build_step_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | docker_commons_plugin | — | — |
| jenkins | git_plugin | — | — |
| jenkins | github_branch_source | <= 2.0.7 | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Jenkins GitHub Branch Source Plugin allows any user with Overall/Read permission to get list of valid credentials IDs
osv·2022-05-17
CVE-2017-1000087 [MEDIUM] Jenkins GitHub Branch Source Plugin allows any user with Overall/Read permission to get list of valid credentials IDs
Jenkins GitHub Branch Source Plugin allows any user with Overall/Read permission to get list of valid credentials IDs
GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those could be used as part of an attack to capture the credentials using another vulnerability. An enumeration of credentials IDs in this plugin now requires the permission to have Extended Read permission (when that permission is enabled; otherwise Configure permission) to the job in whose context credentials are being accessed. If no job context exists, Overall/Administer permission is required.
GHSA
Jenkins GitHub Branch Source Plugin allows any user with Overall/Read permission to get list of valid credentials IDs
ghsa·2022-05-17
CVE-2017-1000087 [MEDIUM] CWE-200 Jenkins GitHub Branch Source Plugin allows any user with Overall/Read permission to get list of valid credentials IDs
Jenkins GitHub Branch Source Plugin allows any user with Overall/Read permission to get list of valid credentials IDs
GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those could be used as part of an attack to capture the credentials using another vulnerability. An enumeration of credentials IDs in this plugin now requires the permission to have Extended Read permission (when that permission is enabled; otherwise Configure permission) to the job in whose context credentials are being accessed. If no job context exists, Overall/Administer permission is required.
Jenkins
Jenkins Security Advisory 2017-07-10
vendor_jenkins·2017-07-10·CVSS 6.5
CVE-2017-1000084 [MEDIUM] Jenkins Security Advisory 2017-07-10
Title: Jenkins Security Advisory 2017-07-10
Jenkins Security Advisory 2017-07-10
This advisory originally recommended upgrading Poll SCM plugin to version 1.4. This was incorrect. Version 1.3.1 contains the fix.
This advisory announces vulnerabilities in these Jenkins plugins:
Docker Commons Plugin
Git Plugin
GitHub Branch Source Plugin
Parameterized Trigger Plugin
Periodic Backup Plugin
Pipeline: Build Step Plugin
Pipeline: Groovy Plugin
Poll SCM Plugin
Role-based Authorization Strategy Plugin
Script Security Plugin
Sidebar Link Plugin
SSH Plugin
Subversion Plugin
Description
Parameterized Trigger Plugin fails to check Item/Build permission
SECURITY-201 / CVE-2017-1000084
Builds in Jenkins are a
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-05
Published