First published: Fri Jan 26 2018(Updated: )
Jenkins Dependency Graph Viewer plugin 0.12 and earlier did not perform permission checks for the API endpoint that modifies the dependency graph, allowing anyone with Overall/Read permission to modify this data.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Dependency Graph Viewer | <=0.12 | |
maven/org.jenkins-ci.plugins:depgraph-view | <=0.12 | 0.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000388 has a moderate severity rating due to unauthorized permission checks allowing modification of crucial data.
To fix CVE-2017-1000388, update the Jenkins Dependency Graph Viewer plugin to version 0.13 or later.
The impact of CVE-2017-1000388 allows users with Overall/Read permission to alter the dependency graph data.
CVE-2017-1000388 affects Jenkins Dependency Graph Viewer plugin versions 0.12 and earlier.
CVE-2017-1000388 can be exploited remotely by any user with Overall/Read permission on the Jenkins server.