CVE-2017-2603

LOW

Jenkins < 2.44 and 2.32.2 - User Data Leak in Disconnected Agents' config.xml API

Title source: llm
STIX 2.1

Description

Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This could leak sensitive data such as API tokens (SECURITY-362).

References (4)

Core 4
Core References
Vendor Advisory x_refsource_confirm
https://jenkins.io/security/advisory/2017-02-01/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95955

Scores

CVSS v3 2.6
EPSS 0.0002
EPSS Percentile 6.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-325 CWE-200
Status published
Products (2)
jenkins/jenkins < 2.44
org.jenkins-ci.main/jenkins-core 0 - 2.32.2Maven
Published May 15, 2018
Tracked Since Feb 18, 2026