CVE-2017-1000399
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
4.3
MEDIUM
CVSS 3.1
EPSS 1.0%
描述
The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/item/(ID)/api showed information about tasks in the queue (typically builds waiting to start). This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API endpoint is now only available for tasks that the current user has access to.
如何修補 CVE-2017-1000399
要修補 CVE-2017-1000399,請將受影響套件升級到下列已修補版本。
- —升級至 2.73.2 或更新版本
CVE-2017-1000399 正在被利用嗎?
低 — EPSS 為 1.0%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2.73.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |