CVE-2017-1000245
published 2017-11-01CVE-2017-1000245: The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are…
PriorityP347critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.44%
70.2th percentile
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | build_step_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | docker_commons_plugin | — | — |
| jenkins | git_plugin | — | — |
| jenkins | github_branch_source_plugin | — | — |
| jenkins | groovy_plugin | — | — |
| jenkins | ids_in_docker_commons_plugin | — | — |
| jenkins | ids_in_github_branch_source_plugin | — | — |
| jenkins | parameterized_trigger_plugin | — | — |
| jenkins | periodic_backup_plugin | — | — |
| jenkins | plugins_like_authorize_project_plugin | — | — |
| jenkins | poll_scm_plugin | — | — |
| jenkins | role-based_authorization_strategy_plugin | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins | sidebar_link_plugin | — | — |
| jenkins | ssh | <= 2.4 | — |
| jenkins | ssh_plugin | — | — |
| jenkins | subversion_plugin | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Jenkins SSH Plugin user passwords for encrypted SSH keys stored in plaintext
osv·2022-05-13
CVE-2017-1000245 [CRITICAL] Jenkins SSH Plugin user passwords for encrypted SSH keys stored in plaintext
Jenkins SSH Plugin user passwords for encrypted SSH keys stored in plaintext
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.
GHSA
Jenkins SSH Plugin user passwords for encrypted SSH keys stored in plaintext
ghsa·2022-05-13
CVE-2017-1000245 [CRITICAL] CWE-522 Jenkins SSH Plugin user passwords for encrypted SSH keys stored in plaintext
Jenkins SSH Plugin user passwords for encrypted SSH keys stored in plaintext
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.
Jenkins
Jenkins Security Advisory 2017-07-10
vendor_jenkins·2017-07-10·CVSS 6.5
CVE-2017-1000084 [MEDIUM] Jenkins Security Advisory 2017-07-10
Title: Jenkins Security Advisory 2017-07-10
Jenkins Security Advisory 2017-07-10
This advisory originally recommended upgrading Poll SCM plugin to version 1.4. This was incorrect. Version 1.3.1 contains the fix.
This advisory announces vulnerabilities in these Jenkins plugins:
Docker Commons Plugin
Git Plugin
GitHub Branch Source Plugin
Parameterized Trigger Plugin
Periodic Backup Plugin
Pipeline: Build Step Plugin
Pipeline: Groovy Plugin
Poll SCM Plugin
Role-based Authorization Strategy Plugin
Script Security Plugin
Sidebar Link Plugin
SSH Plugin
Subversion Plugin
Description
Parameterized Trigger Plugin fails to check Item/Build permission
SECURITY-201 / CVE-2017-1000084
Builds in Jenkins are a
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-11-01
Published