CVE-2017-1000245: Critical severity jenkins vulnerability
Published Nov 1, 2017
·Updated
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.
Affected Software
1 affected component
Jenkins Ssh Jenkins<=2.4
Event History
Nov 1, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000245?
CVE-2017-1000245 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-1000245?
To fix CVE-2017-1000245, upgrade Jenkins SSH Plugin to a version higher than 2.4.
3
What does CVE-2017-1000245 affect?
CVE-2017-1000245 affects the Jenkins SSH Plugin, specifically versions up to 2.4.
4
What risk does CVE-2017-1000245 pose to security?
CVE-2017-1000245 poses a risk of exposing user passwords and passphrases stored in plaintext.
5
Is there a workaround for CVE-2017-1000245?
The only effective workaround for CVE-2017-1000245 is to secure the configuration file containing the plaintext credentials.