CVE-2017-1000086

CVSS v3.0 8 (High)
80% Progress
CVSS v2.0 6 (Medium)
60% Progress
EPSS 0.10 % (42th)
0.10% Progress
Affected Products 1
Advisories 1

The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change its settings, trigger backups, restore backups, download backups, and also delete all previous backups via log rotation. Additionally, the plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks.

Weaknesses
CWE-862
Missing Authorization
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2017-10-05 01:29:03
(7 years ago)
Updated Date
2020-08-24 17:37:01
(4 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Periodic Backup 1.0 for Jenkins cpe:2.3:a:jenkins:periodic_backup:1.0:*:*:*:*:jenkins
  Jenkins Periodic Backup 1.1 for Jenkins cpe:2.3:a:jenkins:periodic_backup:1.1:*:*:*:*:jenkins
  Jenkins Periodic Backup 1.2 for Jenkins cpe:2.3:a:jenkins:periodic_backup:1.2:*:*:*:*:jenkins
  Jenkins Periodic Backup 1.3 for Jenkins cpe:2.3:a:jenkins:periodic_backup:1.3:*:*:*:*:jenkins
  Jenkins Periodic Backup 1.4 for Jenkins cpe:2.3:a:jenkins:periodic_backup:1.4:*:*:*:*:jenkins
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...