CVE-2017-2611
published 2018-05-08CVE-2017-2611: Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
2.04%
79.2th percentile
Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jenkins to trigger these background processes (that are otherwise performed daily), possibly causing additional load on Jenkins master and agents.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | ant_plugin | — | — |
| jenkins | jenkins | < 2.32.2 | 2.32.2 |
| jenkins | jenkins | < 2.44 | 2.44 |
| jenkins | jenkins_core | — | — |
| jenkins | jenkins_lts | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Incorrect Authorization in Jenkins Core
osv·2022-05-13
CVE-2017-2611 [MEDIUM] Incorrect Authorization in Jenkins Core
Incorrect Authorization in Jenkins Core
Jenkins before versions before 2.44 are vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jenkins to trigger these background processes (that are otherwise performed daily), possibly causing additional load on Jenkins master and agents.
GHSA
Incorrect Authorization in Jenkins Core
ghsa·2022-05-13
CVE-2017-2611 [MEDIUM] CWE-863 Incorrect Authorization in Jenkins Core
Incorrect Authorization in Jenkins Core
Jenkins before versions before 2.44 are vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jenkins to trigger these background processes (that are otherwise performed daily), possibly causing additional load on Jenkins master and agents.
Red Hat
jenkins: Insufficient permission check for periodic processes (SECURITY-389)
vendor_redhat·2017-02-01·CVSS 4.3
CVE-2017-2611 [MEDIUM] CWE-358 jenkins: Insufficient permission check for periodic processes (SECURITY-389)
jenkins: Insufficient permission check for periodic processes (SECURITY-389)
Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jenkins to trigger these background processes (that are otherwise performed daily), possibly causing additional load on Jenkins master and agents.
Package: jenkins (Red Hat OpenShift Enterprise 2) - Under investigation
Package: jenkins (Red Hat OpenShift Enterprise 3) - Under investigation
Jenkins
Jenkins Security Advisory 2017-02-01
vendor_jenkins·2017-02-01·CVSS 4.3
CVE-2011-4969 [MEDIUM] Jenkins Security Advisory 2017-02-01
Title: Jenkins Security Advisory 2017-02-01
Jenkins Security Advisory 2017-02-01
This advisory announces multiple vulnerabilities in Jenkins.
Description
Use of AES ECB block cipher mode without IV for encrypting secrets
SECURITY-304 / CVE-2017-2598
Secrets such as passwords are typically stored on disk and sent to users as part of some pages in encrypted form. These were encrypted using AES-128 ECB without IV, which exposes Jenkins and the stored secrets to unnecessary risks. Jenkins now encrypts secrets using AES-128 CBC with random IV.
Items could be created with same name as existing item
SECURITY-321 / CVE-2017-2599
An insufficient permission check allowed users with the permission to create new items (e.g. jobs) to overwrite
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-2611 jenkins: Insufficient permission check for periodic processes (SECURITY-389)
bugzilla·2017-02-02·CVSS 4.3
CVE-2017-2611 [MEDIUM] CVE-2017-2611 jenkins: Insufficient permission check for periodic processes (SECURITY-389)
CVE-2017-2611 jenkins: Insufficient permission check for periodic processes (SECURITY-389)
The following flaw was found in Jenkins:
The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jenkins to trigger these background processes (that are otherwise performed daily), possibly causing additional load on Jenkins master and agents.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2017-02-01
Upstream patch:
https://github.com/jenkinsci/jenkins/commit/97a61a9fe55f4c16168c123f98301a5173b9fa86
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1418736]
Bugzilla
CVE-2017-1000362 CVE-2017-2598 CVE-2017-2599 CVE-2017-2600 CVE-2017-2601 CVE-2017-2602 CVE-2017-2604 CVE-2017-2606 CVE-2017-2607 CVE-2017-2608 CVE-2017-2609 CVE-2017-2610 CVE-2017-2611 CVE-2017-2612 C
bugzilla·2017-02-02·CVSS 9.8
CVE-2017-1000362 [CRITICAL] CVE-2017-1000362 CVE-2017-2598 CVE-2017-2599 CVE-2017-2600 CVE-2017-2601 CVE-2017-2602 CVE-2017-2604 CVE-2017-2606 CVE-2017-2607 CVE-2017-2608 CVE-2017-2609 CVE-2017-2610 CVE-2017-2611 CVE-2017-2612 C
CVE-2017-1000362 CVE-2017-2598 CVE-2017-2599 CVE-2017-2600 CVE-2017-2601 CVE-2017-2602 CVE-2017-2604 CVE-2017-2606 CVE-2017-2607 CVE-2017-2608 CVE-2017-2609 CVE-2017-2610 CVE-2017-2611 CVE-2017-2612 CVE-2017-2613 jenkins: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant
http://www.securityfocus.com/bid/95956https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2611https://github.com/jenkinsci/jenkins/commit/97a61a9fe55f4c16168c123f98301a5173b9fa86https://jenkins.io/security/advisory/2017-02-01/http://www.securityfocus.com/bid/95956https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2611https://github.com/jenkinsci/jenkins/commit/97a61a9fe55f4c16168c123f98301a5173b9fa86https://jenkins.io/security/advisory/2017-02-01/
2018-05-08
Published