cbcvebase.
CVE-2017-1000387
published 2018-01-26

CVE-2017-1000387: Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file…

PriorityP335high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.38%
29.6th percentile
Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.BuildPublisher.xml in the Jenkins master home directory. These credentials were stored unencrypted, allowing anyone with local file system access to access them. Additionally, the credentials were also transmitted in plain text as part of the configuration form. This could result in exposure of the credentials through browser extensions, cross-site scripting vulnerabilities, and similar situations.

Affected

7 ranges
VendorProductVersion rangeFixed in
jenkinsall_versions_of_scp_publisher_plugin
jenkinsbuild-publisher<= 1.21
jenkinsbuild-publisher_plugin
jenkinsdependency_graph_viewer_plugin
jenkinsmultijob_plugin
jenkinsscp_publisher_plugin
jenkinsurls_provided_by_global-build-stats_plugin

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.