CVE-2017-1000362
CRITICALJenkins 1.498-2.32.1 - Unprotected Sensitive Data Exposure via Re-key Admin Monitor Backups
Title source: llmDescription
The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It also created a backup directory with all old secrets, and the key used to encrypt them. These backups were world-readable and not removed afterwards. Jenkins now deletes the backup directory, if present. Upgrading from before 1.498 will no longer create a backup directory. Administrators relying on file access permissions in their manually created backups are advised to check them for the directory $JENKINS_HOME/jenkins.security.RekeySecretAdminMonitor/backups, and delete it if present.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://jenkins.io/security/advisory/2017-02-01/
Scores
CVSS v3
9.8
EPSS
0.0123
EPSS Percentile
79.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-200
Status
published
Products (2)
jenkins/jenkins
< 1.498
org.jenkins-ci.main/jenkins-core
1.498 - 2.32.2Maven
Published
Jul 17, 2017
Tracked Since
Feb 18, 2026