CVE-2017-1000400

MEDIUM

Jenkins <2.73.1, <2.83 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream and downstream projects. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API now only lists upstream and downstream projects that the current user has access to.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://jenkins.io/security/advisory/2017-10-11/

Scores

CVSS v3 4.3
EPSS 0.0011
EPSS Percentile 29.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-862
Status published
Products (3)
jenkins/jenkins < 2.73.1
jenkins/jenkins < 2.83
org.jenkins-ci.main/jenkins-core 0 - 2.73.2Maven
Published Jan 26, 2018
Tracked Since Feb 18, 2026