CVE-2017-16520

HIGH

Inedo BuildMaster <5.8.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://inedo.myjetbrains.com/youtrack/issue/BM-3107
Vendor Advisory x_refsource_confirm
https://inedo.com/blog/buildmaster-582-released
Vendor Advisory x_refsource_confirm
https://inedo.com/buildmaster/versions#v5.8

Scores

CVSS v3 7.5
EPSS 0.0106
EPSS Percentile 60.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-269
Status published
Products (1)
inedo/buildmaster < 5.8.2
Published Nov 11, 2017
Tracked Since Feb 18, 2026