CVE-2017-1000104
published 2017-10-05CVE-2017-1000104: The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read…
PriorityP434medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
0.82%
53.0th percentile
The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were able to access URLs directly that allowed viewing these files. Access to view these files now requires sufficient permissions to configure the provided files, view the configuration of the folder in which the configuration files are defined, or have Job/Configure permissions to a job able to use these files.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | blue_ocean_plugin | — | — |
| jenkins | config_file_provider | <= 2.16.1 | — |
| jenkins | config_file_provider_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | datadog_plugin | — | — |
| jenkins | deploy_to_container_plugin | — | — |
| jenkins | dry_plugin | — | — |
| jenkins | groovy_plugin | — | — |
| jenkins | input_step_plugin | — | — |
| jenkins | owasp_dependency-check_plugin | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins | static_analysis_utilities_plugin | — | — |
| jenkins | warnings_plugin | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Privilege Management in Jenkins Config File Provider Plugin
osv·2022-05-13
CVE-2017-1000104 [MEDIUM] Improper Privilege Management in Jenkins Config File Provider Plugin
Improper Privilege Management in Jenkins Config File Provider Plugin
The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were able to access URLs directly that allowed viewing these files. Access to view these files now requires sufficient permissions to configure the provided files, view the configuration of the folder in which the configuration files are defined, or have Job/Configure permissions to a job able to use these files.
GHSA
Improper Privilege Management in Jenkins Config File Provider Plugin
ghsa·2022-05-13
CVE-2017-1000104 [MEDIUM] CWE-269 Improper Privilege Management in Jenkins Config File Provider Plugin
Improper Privilege Management in Jenkins Config File Provider Plugin
The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were able to access URLs directly that allowed viewing these files. Access to view these files now requires sufficient permissions to configure the provided files, view the configuration of the folder in which the configuration files are defined, or have Job/Configure permissions to a job able to use these files.
Jenkins
Jenkins Security Advisory 2017-08-07
vendor_jenkins·2017-08-07·CVSS 5.4
CVE-2017-1000102 [MEDIUM] Jenkins Security Advisory 2017-08-07
Title: Jenkins Security Advisory 2017-08-07
Jenkins Security Advisory 2017-08-07
This advisory announces vulnerabilities in these Jenkins plugins:
Blue Ocean
Config File Provider Plugin
Datadog Plugin
Deploy to container Plugin
DRY Plugin
OWASP Dependency-Check Plugin
Pipeline: Groovy Plugin
Pipeline: Input Step Plugin
Script Security Plugin
Static Analysis Utilities Plugin
Description
Persistent XSS vulnerability in Static Analysis Utilities and DRY Plugins
SECURITY-467 / CVE-2017-1000102 (Static Analysis Utilities Plugin) / CVE-2017-1000103 (DRY Plugin)
The "Details" view of Static Analysis Utilities based plugins, as well as the custom "Details" view of the DRY Plugin, was vulnerable to a persisted cross-site
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-05
Published