CVE-2017-1000397
published 2018-01-26CVE-2017-1000397: Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL…
PriorityP425medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
0.49%
39.1th percentile
Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | client_needs_to_be_updated_independently_from_the_plugin | — | — |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| jenkins | jenkins_weekly | — | — |
| jenkins | mailer_plugin | — | — |
| jenkins | maven | <= 2.17 | — |
| jenkins | maven_plugin | — | — |
| jenkins | please_note_that_swarm_plugin | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins | swarm_plugin | — | — |
| jenkins | updating_just_the_plugin | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa4.3MEDIUM
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Jenkins
Jenkins Security Advisory 2017-10-11
vendor_jenkins·2017-10-11·CVSS 7.5
CVE-2012-6153 [HIGH] Jenkins Security Advisory 2017-10-11
Title: Jenkins Security Advisory 2017-10-11
Jenkins Security Advisory 2017-10-11
This advisory announces multiple vulnerabilities in Jenkins (weekly and LTS), and these plugins:
Maven Plugin
Swarm Plugin Client
Speaks! Plugin
Description
Arbitrary shell command execution on controller by users with Agent-related permissions
SECURITY-478 / CVE-2017-1000393
Users with permission to create or configure agents in Jenkins could configure a launch method called Launch agent via execution of command on master .
This allowed them to run arbitrary shell commands on the Jenkins controller whenever the agent was supposed to be launched.
Configuration of this launch method now requires the Run Scripts permission typically only granted t
GHSA
MitM on Jenkins Maven Plugin
ghsa·2022-05-14·CVSS 4.3
CVE-2017-1000397 [MEDIUM] CWE-20 MitM on Jenkins Maven Plugin
MitM on Jenkins Maven Plugin
Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient.
OSV
MitM on Jenkins Maven Plugin
osv·2022-05-14·CVSS 4.3
CVE-2017-1000397 [MEDIUM] MitM on Jenkins Maven Plugin
MitM on Jenkins Maven Plugin
Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-01-26
Published