CVE-2017-1000104: Medium severity jenkins config file provider vulnerability
The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were able to access URLs directly that allowed viewing these files. Access to view these files now requires sufficient permissions to configure the provided files, view the configuration of the folder in which the configuration files are defined, or have Job/Configure permissions to a job able to use these files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000104?
CVE-2017-1000104 has a medium severity rating due to unauthorized access to sensitive configuration files.
How do I fix CVE-2017-1000104?
To fix CVE-2017-1000104, upgrade the Config File Provider Plugin to version 2.16.2 or later.
Who is affected by CVE-2017-1000104?
Users of Jenkins with the Config File Provider Plugin versions up to 2.16.1 are affected by CVE-2017-1000104.
What does CVE-2017-1000104 exploit?
CVE-2017-1000104 exploits insufficient access restrictions, allowing users with Overall/Read access to view sensitive configuration files.
Can CVE-2017-1000104 lead to data exposure?
Yes, CVE-2017-1000104 can lead to data exposure of sensitive information such as passwords found in configuration files.