CVE-2017-1000091
published 2017-10-05CVE-2017-1000091: GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to verify Scan…
PriorityP336medium6.3CVSS 3.0
AVNACLPRLUINSUCLILAL
EPSS
0.64%
46.5th percentile
GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to verify Scan Credentials are correct). This functionality improperly checked permissions, allowing any user with Overall/Read access to Jenkins to connect to any web server and send credentials with a known ID, thereby possibly capturing them. Additionally, this functionality did not require POST requests be used, thereby allowing the above to be performed without direct access to Jenkins via Cross-Site Request Forgery.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | build_step_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | docker_commons_plugin | — | — |
| jenkins | git_plugin | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
| jenkins | github_branch_source | — | — |
CVSS provenance
nvdv3.06.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Jenkins GitHub Branch Source Plugin vulnerable to Cross-Site Request Forgery
ghsa·2022-05-17
CVE-2017-1000091 [MEDIUM] CWE-352 Jenkins GitHub Branch Source Plugin vulnerable to Cross-Site Request Forgery
Jenkins GitHub Branch Source Plugin vulnerable to Cross-Site Request Forgery
GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to verify Scan Credentials are correct). This functionality improperly checked permissions, allowing any user with Overall/Read access to Jenkins to connect to any web server and send credentials with a known ID, thereby possibly capturing them. Additionally, this functionality did not require POST requests be used, thereby allowing the above to be performed without direct access to Jenkins via Cross-Site Request Forgery. An enumeration of credentials IDs in this plugin now requires the permission to have Extended Read permission (when that permission is enabled; otherwi
OSV
Jenkins GitHub Branch Source Plugin vulnerable to Cross-Site Request Forgery
osv·2022-05-17
CVE-2017-1000091 [MEDIUM] Jenkins GitHub Branch Source Plugin vulnerable to Cross-Site Request Forgery
Jenkins GitHub Branch Source Plugin vulnerable to Cross-Site Request Forgery
GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to verify Scan Credentials are correct). This functionality improperly checked permissions, allowing any user with Overall/Read access to Jenkins to connect to any web server and send credentials with a known ID, thereby possibly capturing them. Additionally, this functionality did not require POST requests be used, thereby allowing the above to be performed without direct access to Jenkins via Cross-Site Request Forgery. An enumeration of credentials IDs in this plugin now requires the permission to have Extended Read permission (when that permission is enabled; otherwi
Jenkins
Jenkins Security Advisory 2017-07-10
vendor_jenkins·2017-07-10·CVSS 6.5
CVE-2017-1000084 [MEDIUM] Jenkins Security Advisory 2017-07-10
Title: Jenkins Security Advisory 2017-07-10
Jenkins Security Advisory 2017-07-10
This advisory originally recommended upgrading Poll SCM plugin to version 1.4. This was incorrect. Version 1.3.1 contains the fix.
This advisory announces vulnerabilities in these Jenkins plugins:
Docker Commons Plugin
Git Plugin
GitHub Branch Source Plugin
Parameterized Trigger Plugin
Periodic Backup Plugin
Pipeline: Build Step Plugin
Pipeline: Groovy Plugin
Poll SCM Plugin
Role-based Authorization Strategy Plugin
Script Security Plugin
Sidebar Link Plugin
SSH Plugin
Subversion Plugin
Description
Parameterized Trigger Plugin fails to check Item/Build permission
SECURITY-201 / CVE-2017-1000084
Builds in Jenkins are a
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-05
Published