CVE-2017-1000108

CVSS v3.0 7.5 (High)
75% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.12 % (47th)
0.12% Progress
Affected Products 1
Advisories 1

The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item/Build permission instead.

Weaknesses
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2017-10-05 01:29:04
(7 years ago)
Updated Date
2017-11-01 13:54:00
(6 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Pipeline-input-step 2.0 for Jenkins cpe:2.3:a:jenkins:pipeline-input-step:2.0:*:*:*:*:jenkins
  Jenkins Pipeline-input-step 2.1 for Jenkins cpe:2.3:a:jenkins:pipeline-input-step:2.1:*:*:*:*:jenkins
  Jenkins Pipeline-input-step 2.2 for Jenkins cpe:2.3:a:jenkins:pipeline-input-step:2.2:*:*:*:*:jenkins
  Jenkins Pipeline-input-step 2.3 for Jenkins cpe:2.3:a:jenkins:pipeline-input-step:2.3:*:*:*:*:jenkins
  Jenkins Pipeline-input-step 2.4 for Jenkins cpe:2.3:a:jenkins:pipeline-input-step:2.4:*:*:*:*:jenkins
  Jenkins Pipeline-input-step 2.5 for Jenkins cpe:2.3:a:jenkins:pipeline-input-step:2.5:*:*:*:*:jenkins
  Jenkins Pipeline-input-step 2.6 for Jenkins cpe:2.3:a:jenkins:pipeline-input-step:2.6:*:*:*:*:jenkins
  Jenkins Pipeline-input-step 2.7 for Jenkins cpe:2.3:a:jenkins:pipeline-input-step:2.7:*:*:*:*:jenkins
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...