cbcvebase.
CVE-2017-1000104
published 2017-10-05

CVE-2017-1000104: The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read…

PriorityP434medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
0.82%
53.0th percentile
The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were able to access URLs directly that allowed viewing these files. Access to view these files now requires sufficient permissions to configure the provided files, view the configuration of the folder in which the configuration files are defined, or have Job/Configure permissions to a job able to use these files.

Affected

13 ranges
VendorProductVersion rangeFixed in
jenkinsblue_ocean_plugin
jenkinsconfig_file_provider<= 2.16.1
jenkinsconfig_file_provider_plugin
jenkinscredentials_plugin
jenkinsdatadog_plugin
jenkinsdeploy_to_container_plugin
jenkinsdry_plugin
jenkinsgroovy_plugin
jenkinsinput_step_plugin
jenkinsowasp_dependency-check_plugin
jenkinsscript_security_plugin
jenkinsstatic_analysis_utilities_plugin
jenkinswarnings_plugin

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.