SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-2599

Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check.

MEDIUM 5.4EPSS 1.10%

Does this matter?

Lower severity and a low EPSS score (1.10%). Track it; it rarely justifies an emergency change on its own.

Description

Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS
1.10% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-863
Affected
jenkins/jenkins
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.