CVE-2017-2611
Summary
| CVE | CVE-2017-2611 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-08 18:29:00 UTC |
| Updated | 2020-09-09 14:56:00 UTC |
| Description | Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jenkins to trigger these background processes (that are otherwise performed daily), possibly causing additional load on Jenkins master and agents. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jenkins | Jenkins | All | All | All | All |
| Application | Jenkins | Jenkins | All | All | All | All |
| Application | Jenkins | Jenkins | All | All | All | All |
| Application | Jenkins | Jenkins | All | All | All | All |
| Application | Redhat | Openshift | 2.0 | All | All | All |
| Application | Redhat | Openshift | 3.0 | All | All | All |
| Application | Redhat | Openshift | 2.0 | All | All | All |
| Application | Redhat | Openshift | 3.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Merge pull request #99 from jenkinsci-cert/SECURITY-389 · jenkinsci/jenkins@97a61a9 · GitHub | CONFIRM | github.com | Third Party Advisory |
| 1418729 – (CVE-2017-2611) CVE-2017-2611 jenkins: Insufficient permission check for periodic processes (SECURITY-389) | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| Jenkins Security Advisory 2017-02-01 | CONFIRM | jenkins.io | Vendor Advisory |
| Jenkins CVE-2017-2611 Multiple Security Bypass Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.