CVE-2017-1000504: CSRF
A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of execution of commands during initialization. There is a very short window of time after startup during which Jenkins may no longer show the 'Please wait while Jenkins is getting ready to work' message but Cross-Site Request Forgery (CSRF) protection may not yet be effective.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000504?
CVE-2017-1000504 has been rated as a medium severity vulnerability.
How do I fix CVE-2017-1000504?
To fix CVE-2017-1000504, upgrade Jenkins to version 2.95 or later.
Which versions of Jenkins are affected by CVE-2017-1000504?
CVE-2017-1000504 affects Jenkins versions 2.94 and earlier, as well as 2.89.1 and earlier.
What is the nature of the issue in CVE-2017-1000504?
CVE-2017-1000504 describes a race condition during the startup of Jenkins that could lead to improper command execution.
Are there any quick workarounds for CVE-2017-1000504?
There are no recommended workarounds for CVE-2017-1000504; the best approach is to apply the patch by upgrading.