First published: Wed Oct 04 2017(Updated: )
Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jenkins-ci.plugins:pipeline-build-step | <=2.5 | 2.5.1 |
Jenkins Pipeline | <=2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000089 is classified as a medium severity vulnerability.
To fix CVE-2017-1000089, upgrade the Pipeline: Build Step Plugin to version 2.5.1 or later.
CVE-2017-1000089 affects Jenkins installations utilizing the Pipeline: Build Step Plugin version up to 2.5.
The impact of CVE-2017-1000089 allows unauthorized triggering of any project in Jenkins, potentially compromising workflows.
CVE-2017-1000089 was disclosed on July 10, 2017.