CVE-2017-1000089 — Incorrect Default Permissions in Jenkins Pipeline
Severity
5.3MEDIUMNVD
EPSS
0.0%
top 91.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 5
Latest updateMay 13
Description
Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages1 packages
🔴Vulnerability Details
3CVEList▶
CVE-2017-1000089: Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins↗2017-10-04
📋Vendor Advisories
2💬Community
1Bugzilla▶
CVE-2017-1000089 jenkins-plugin-pipeline-build-step: Missing check of Item/Build permission (SECURITY-433)↗2017-07-14