CVE-2017-1000089: Medium severity jenkins pipeline vulnerability
Published Oct 4, 2017
·Updated
Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.
Affected Software
2 affected componentsFixes available
maven/org.jenkins-ci.plugins:pipeline-build-step<=2.5
2.5.1
Jenkins Pipeline\<=2.5
Event History
Oct 4, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
May 13, 2022
Advisory Published
via GitHub·01:40 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-1000089?
CVE-2017-1000089 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-1000089?
To fix CVE-2017-1000089, upgrade the Pipeline: Build Step Plugin to version 2.5.1 or later.
3
What does CVE-2017-1000089 affect?
CVE-2017-1000089 affects Jenkins installations utilizing the Pipeline: Build Step Plugin version up to 2.5.
4
What is the impact of CVE-2017-1000089?
The impact of CVE-2017-1000089 allows unauthorized triggering of any project in Jenkins, potentially compromising workflows.
5
When was CVE-2017-1000089 disclosed?
CVE-2017-1000089 was disclosed on July 10, 2017.