First published: Sat Feb 23 2013(Updated: )
Jenkins Security Advisory 2013-02-16 A malicious user of Jenkins can trick Jenkins into building jobs that he does not have direct access to. <a href="https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16">https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Jenkins | <=1.480.2 | |
Jenkins Jenkins | <=1.501 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0330 is classified as a medium severity vulnerability due to the potential unauthorized access to Jenkins jobs.
To fix CVE-2013-0330, upgrade Jenkins to version 1.480.3 or later if using the LTS version, or to 1.501 or later for other versions.
CVE-2013-0330 affects Jenkins versions up to and including 1.480.2 and up to and including 1.501.
A malicious user can exploit CVE-2013-0330 to build jobs they do not have direct access to within Jenkins.
Yes, CVE-2013-0330 indicates that the user access control in Jenkins can be circumvented, allowing unauthorized job builds.