CVE-2017-1000105: Medium severity jenkins vulnerability
The optional Run/Artifacts permission can be enabled by setting a Java system property.
Blue Ocean did not check this permission before providing access to archived artifacts, Item/Read permission was sufficient.
Blue Ocean now correctly checks the Run/Artifacts permission if it’s enabled before providing access to artifacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000105?
CVE-2017-1000105 is classified as a medium severity vulnerability due to its potential to expose sensitive data.
How do I fix CVE-2017-1000105?
To fix CVE-2017-1000105, ensure that the Run/Artifacts permission is enabled and verify the access control settings in Jenkins Blue Ocean.
What versions are affected by CVE-2017-1000105?
CVE-2017-1000105 affects Jenkins Blue Ocean versions up to 1.1.5 and 1.2.0-beta versions up to 1.2.0-beta-3.
What does CVE-2017-1000105 exploit?
CVE-2017-1000105 exploits a lack of permission checks in Jenkins Blue Ocean that allows unauthorized access to archived artifacts.
Is CVE-2017-1000105 a code execution vulnerability?
No, CVE-2017-1000105 does not allow for code execution but it does enable unauthorized access to secured resources.