CVE-2017-1000106
published 2017-10-05CVE-2017-1000106: Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a…
PriorityP347high8.5CVSS 3.0
AVNACLPRLUINSCCLIHAN
EPSS
0.76%
51.1th percentile
Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines in Jenkins. Its SCM content REST API supports the pipeline creation and editing feature in Blue Ocean. The SCM content REST API did not check the current user's authentication or credentials. If the GitHub organization folder was created via Blue Ocean, it retained a reference to its creator's GitHub credentials. This allowed users with read access to the GitHub organization folder to create arbitrary commits in the repositories inside the GitHub organization corresponding to the GitHub organization folder with the GitHub credentials of the creator of the organization folder. Additionally, users with read access to the GitHub organization folder could read arbitrary file contents from the repositories inside the GitHub organization corresponding to the GitHub organization folder if the branch contained a Jenkinsfile (which could be created using the other part of this vulnerability), and they could provide the organization folder name, repository name, branch name, and file name.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | blue_ocean | <= 1.1.5 | — |
| jenkins | blue_ocean | — | — |
| jenkins | blue_ocean_plugin | — | — |
| jenkins | config_file_provider_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | datadog_plugin | — | — |
| jenkins | deploy_to_container_plugin | — | — |
| jenkins | dry_plugin | — | — |
| jenkins | groovy_plugin | — | — |
| jenkins | input_step_plugin | — | — |
| jenkins | owasp_dependency-check_plugin | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins | static_analysis_utilities_plugin | — | — |
| jenkins | warnings_plugin | — | — |
CVSS provenance
nvdv3.08.5HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Authentication in Jenkins Blue Ocean Plugin
ghsa·2022-05-13
CVE-2017-1000106 [HIGH] CWE-287 Improper Authentication in Jenkins Blue Ocean Plugin
Improper Authentication in Jenkins Blue Ocean Plugin
Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines in Jenkins. Its SCM content REST API supports the pipeline creation and editing feature in Blue Ocean. The SCM content REST API did not check the current user's authentication or credentials. If the GitHub organization folder was created via Blue Ocean, it retained a reference to its creator's GitHub credentials. This allowed users with read access to the GitHub organization folder to create arbitrary commits in the repositories inside the GitHub organization corresponding to the GitHub organization folder with the GitHub credentials of the
OSV
Improper Authentication in Jenkins Blue Ocean Plugin
osv·2022-05-13
CVE-2017-1000106 [HIGH] Improper Authentication in Jenkins Blue Ocean Plugin
Improper Authentication in Jenkins Blue Ocean Plugin
Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines in Jenkins. Its SCM content REST API supports the pipeline creation and editing feature in Blue Ocean. The SCM content REST API did not check the current user's authentication or credentials. If the GitHub organization folder was created via Blue Ocean, it retained a reference to its creator's GitHub credentials. This allowed users with read access to the GitHub organization folder to create arbitrary commits in the repositories inside the GitHub organization corresponding to the GitHub organization folder with the GitHub credentials of the
Jenkins
Jenkins Security Advisory 2017-08-07
vendor_jenkins·2017-08-07·CVSS 5.4
CVE-2017-1000102 [MEDIUM] Jenkins Security Advisory 2017-08-07
Title: Jenkins Security Advisory 2017-08-07
Jenkins Security Advisory 2017-08-07
This advisory announces vulnerabilities in these Jenkins plugins:
Blue Ocean
Config File Provider Plugin
Datadog Plugin
Deploy to container Plugin
DRY Plugin
OWASP Dependency-Check Plugin
Pipeline: Groovy Plugin
Pipeline: Input Step Plugin
Script Security Plugin
Static Analysis Utilities Plugin
Description
Persistent XSS vulnerability in Static Analysis Utilities and DRY Plugins
SECURITY-467 / CVE-2017-1000102 (Static Analysis Utilities Plugin) / CVE-2017-1000103 (DRY Plugin)
The "Details" view of Static Analysis Utilities based plugins, as well as the custom "Details" view of the DRY Plugin, was vulnerable to a persisted cross-site
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-05
Published