First published: Tue May 15 2018(Updated: )
Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This could leak sensitive data such as API tokens (SECURITY-362).
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins LTS | <2.44 | |
Jenkins LTS | <2.32.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2603 has a medium severity level as it allows for the potential leakage of sensitive user data.
To fix CVE-2017-2603, upgrade Jenkins to version 2.44 or later, or 2.32.2 or later.
CVE-2017-2603 can expose sensitive data such as API tokens through the disconnected agents' config.xml API.
Jenkins versions prior to 2.44 and 2.32.2 are affected by CVE-2017-2603.
Yes, CVE-2017-2603 can potentially lead to unauthorized access if sensitive data like API tokens are leaked.