Jenkins CVE-2017-1000399 Information Disclosure Vulnerability
BID:104305
Info
Jenkins CVE-2017-1000399 Information Disclosure Vulnerability
| Bugtraq ID: | 104305 |
| Class: | Design Error |
| CVE: |
CVE-2017-1000399 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2017 12:00AM |
| Updated: | Nov 10 2017 12:00AM |
| Credit: | Jesse Glick, CloudBees, Inc. |
| Vulnerable: |
Jenkins-Ci Jenkins LTS 2.73.1 Jenkins-Ci Jenkins LTS 2.32.1 Jenkins-Ci Jenkins LTS 2.19.3 Jenkins-Ci Jenkins LTS 2.19.2 Jenkins-Ci Jenkins LTS 1.652.2 Jenkins-Ci Jenkins LTS 1.651.2 Jenkins-Ci Jenkins LTS 1.651.1 Jenkins-Ci Jenkins LTS 1.642.2 Jenkins-Ci Jenkins LTS 1.642.1 Jenkins-Ci Jenkins LTS 1.625.3 Jenkins-Ci Jenkins LTS 1.625.2 Jenkins-Ci Jenkins LTS 1.625.1 Jenkins-Ci Jenkins LTS 1.609.1 Jenkins-Ci Jenkins LTS 1.580.1 Jenkins-Ci Jenkins LTS 1.565.3 Jenkins-Ci Jenkins 2.73.2 Jenkins-Ci Jenkins 1.7.24 Jenkins-Ci Jenkins 2.83 Jenkins-Ci Jenkins 2.57 Jenkins-Ci Jenkins 2.56 Jenkins-Ci Jenkins 2.44 Jenkins-Ci Jenkins 2.43 Jenkins-Ci Jenkins 2.32 Jenkins-Ci Jenkins 2.31 Jenkins-Ci Jenkins 2.3 Jenkins-Ci Jenkins 2.2 Jenkins-Ci Jenkins 2.1 Jenkins-Ci Jenkins 2.0 Jenkins-Ci Jenkins 1.7.24.1 Jenkins-Ci Jenkins 1.656 Jenkins-Ci Jenkins 1.655 Jenkins-Ci Jenkins 1.654 Jenkins-Ci Jenkins 1.653 Jenkins-Ci Jenkins 1.652 Jenkins-Ci Jenkins 1.651 Jenkins-Ci Jenkins 1.650 Jenkins-Ci Jenkins 1.649 Jenkins-Ci Jenkins 1.641 Jenkins-Ci Jenkins 1.640 Jenkins-Ci Jenkins 1.638 Jenkins-Ci Jenkins 1.637 Jenkins-Ci Jenkins 1.600 Jenkins-Ci Jenkins 1.587 Jenkins-Ci Jenkins 1.578 Jenkins-Ci Jenkins 1.551 Jenkins-Ci Jenkins 1.550 Jenkins-Ci Jenkins 1.532.2 Jenkins-Ci Jenkins 1.532.1 Jenkins-Ci Jenkins 1.523 Jenkins-Ci Jenkins 1.514 Jenkins-Ci Jenkins 1.513 Jenkins-Ci Jenkins 1.509.1 Jenkins-Ci Jenkins 1.509 Jenkins-Ci Jenkins 1.502 |
| Not Vulnerable: |
Jenkins-Ci Jenkins LTS 2.73.2 Jenkins-Ci Jenkins 2.84 |
Discussion
Jenkins CVE-2017-1000399 Information Disclosure Vulnerability
Jenkins is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks.
The following versions are affected:
Jenkins 2.83 and prior versions.
Jenkins LTS 2.73.1 and prior versions.
Jenkins is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks.
The following versions are affected:
Jenkins 2.83 and prior versions.
Jenkins LTS 2.73.1 and prior versions.
Exploit / POC
Jenkins CVE-2017-1000399 Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Jenkins CVE-2017-1000399 Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Jenkins CVE-2017-1000399 Information Disclosure Vulnerability
References:
References:
- Jenkins CI Homepage (Jenkins CI)
- Jenkins Security Advisory 2017-10-11 (jenkins.io)