356
VMScore

CVE-2017-1000398

Published: 26/01/2018 Updated: 08/05/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The remote API in Jenkins 2.73.1 and previous versions, 2.83 and previous versions at /computer/(agent-name)/api showed information about tasks (typically builds) currently running on that agent. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API now only shows information about accessible tasks.

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins jenkins

Vendor Advisories

The remote API in Jenkins 2731 and earlier, 283 and earlier at /computer/(agent-name)/api showed information about tasks (typically builds) currently running on that agent This included information about tasks that the current user otherwise has no access to, eg due to lack of Item/Read permission This has been fixed, and the API now only sh ...