← Back

CVE-2017-1000087

nvd nist
Published: Oct 5, 2017Modified: May 13, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those could be used as part of an attack to capture the credentials using another vulnerability.

Affected (40)

1 product
Github Branch Source
Configuration A
40 vulnerable
Vulnerable SoftwareAffected Versions
Jenkins
Up to 2.0.7
Version 0.1 beta-1
Version 0.1 beta-2
Version 0.1 beta-3
Version 0.1 beta-4
Version 1.0
Version 1.10
Version 1.1
Version 1.2
Version 1.3
Version 1.4
Version 1.4 beta-1
Version 1.5
Version 1.6
Version 1.7
Version 1.8.1
Version 1.8
Version 1.9
Version 2.0.0
Version 2.0.0 beta-1
Version 2.0.0 beta-2
Version 2.0.1
Version 2.0.1 beta-1
Version 2.0.1 beta-2
Version 2.0.1 beta-3
Version 2.0.1 beta-4
Version 2.0.1 beta-5
Version 2.0.1 beta-6
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.4 beta-1
Version 2.0.5
Version 2.0.6
Version 2.2.0
Version 2.2.0 alpha-1
Version 2.2.0 alpha-2
Version 2.2.0 alpha-3
Version 2.2.0 alpha-4
Version 2.2.0 beta-1

References (2)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.