VulnerabilityModified
CVE-2017-2606
Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to item names that should not be visible (SECURITY-380).
MEDIUM 4.3EPSS 1.91%
Does this matter?
Lower severity and a low EPSS score (1.91%). Track it; it rarely justifies an emergency change on its own.
Description
Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to item names that should not be visible (SECURITY-380). This only affects anonymous users (other users legitimately have access) that were able to get a list of items via an UnprotectedRootAction.
- CVSS 3.0
- 4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.91% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- jenkins/jenkins
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/95962Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2606Issue Tracking
- https://github.com/jenkinsci/jenkins/commit/09cfbc9cd5c9df7c763bc976b7f5c51266b63719Third Party Advisory
- https://jenkins.io/security/advisory/2017-02-01/Vendor Advisory
- http://www.securityfocus.com/bid/95962Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2606Issue Tracking
- https://github.com/jenkinsci/jenkins/commit/09cfbc9cd5c9df7c763bc976b7f5c51266b63719Third Party Advisory
- https://jenkins.io/security/advisory/2017-02-01/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.