cbcvebase.
CVE-2017-1000089
published 2017-10-05

CVE-2017-1000089: Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The…

PriorityP425medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
0.96%
57.5th percentile
Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.

Affected

18 ranges
VendorProductVersion rangeFixed in
jenkinsbuild_step_plugin
jenkinscredentials_plugin
jenkinsdocker_commons_plugin
jenkinsgit_plugin
jenkinsgithub_branch_source_plugin
jenkinsgroovy_plugin
jenkinsids_in_docker_commons_plugin
jenkinsids_in_github_branch_source_plugin
jenkinsparameterized_trigger_plugin
jenkinsperiodic_backup_plugin
jenkinspipeline<= 2.5
jenkinsplugins_like_authorize_project_plugin
jenkinspoll_scm_plugin
jenkinsrole-based_authorization_strategy_plugin
jenkinsscript_security_plugin
jenkinssidebar_link_plugin
jenkinsssh_plugin
jenkinssubversion_plugin

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.