4.3
CVSSv3

CVE-2017-1000400

Published: 26/01/2018 Updated: 24/08/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The Jenkins 2.73.1 and previous versions, 2.83 and previous versions remote API at /job/(job-name)/api contained information about upstream and downstream projects. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API now only lists upstream and downstream projects that the current user has access to.

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins jenkins

Vendor Advisories

The Jenkins 2731 and earlier, 283 and earlier remote API at /job/(job-name)/api contained information about upstream and downstream projects This included information about tasks that the current user otherwise has no access to, eg due to lack of Item/Read permission This has been fixed, and the API now only lists upstream and downstream pro ...