CVE-2017-1000398
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
4.3
MEDIUM
CVSS 3.1
EPSS 1.0%
描述
The remote API in Jenkins 2.73.1 and earlier, 2.83 and earlier at /computer/(agent-name)/api showed information about tasks (typically builds) currently running on that agent. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API now only shows information about accessible tasks.
如何修補 CVE-2017-1000398
要修補 CVE-2017-1000398,請將受影響套件升級到下列已修補版本。
- —升級至 2.73.2 或更新版本
CVE-2017-1000398 正在被利用嗎?
低 — EPSS 為 1.0%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2.73.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |