CVE-2017-1000395

Jenkins 2.73.1 and earlier, 2.83 and earlier provides information about Jenkins user accounts which is generally available to anyone with Overall/Read permissions via the /user/(username)/api remote API. This included e.g. Jenkins users' email addresses if the Mailer Plugin is installed. The remote API now no longer includes information beyond the most basic (user ID and name) unless the user requesting it is a Jenkins administrator.
References
Link Resource
https://jenkins.io/security/advisory/2017-10-11/ Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*

History

No history.

Information

Published : 2018-01-26 02:29

Updated : 2024-02-04 19:46


NVD link : CVE-2017-1000395

Mitre link : CVE-2017-1000395

CVE.ORG link : CVE-2017-1000395


JSON object : View

Products Affected

jenkins

  • jenkins
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor