Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-1000084


Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.


Published

2017-10-05T01:29:03.510

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-276

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins parameterized_trigger 1.0 Yes
Application jenkins parameterized_trigger 1.1 Yes
Application jenkins parameterized_trigger 1.2 Yes
Application jenkins parameterized_trigger 1.3 Yes
Application jenkins parameterized_trigger 1.4 Yes
Application jenkins parameterized_trigger 1.5 Yes
Application jenkins parameterized_trigger 1.6 Yes
Application jenkins parameterized_trigger 2.0 Yes
Application jenkins parameterized_trigger 2.1 Yes
Application jenkins parameterized_trigger 2.2 Yes
Application jenkins parameterized_trigger 2.3 Yes
Application jenkins parameterized_trigger 2.4 Yes
Application jenkins parameterized_trigger 2.5 Yes
Application jenkins parameterized_trigger 2.6 Yes
Application jenkins parameterized_trigger 2.7 Yes
Application jenkins parameterized_trigger 2.8 Yes
Application jenkins parameterized_trigger 2.9 Yes
Application jenkins parameterized_trigger 2.10 Yes
Application jenkins parameterized_trigger 2.11 Yes
Application jenkins parameterized_trigger 2.12 Yes
Application jenkins parameterized_trigger 2.13 Yes
Application jenkins parameterized_trigger 2.14 Yes
Application jenkins parameterized_trigger 2.15 Yes
Application jenkins parameterized_trigger 2.16 Yes
Application jenkins parameterized_trigger 2.17 Yes
Application jenkins parameterized_trigger 2.18 Yes
Application jenkins parameterized_trigger 2.19 Yes
Application jenkins parameterized_trigger 2.20 Yes
Application jenkins parameterized_trigger 2.21 Yes
Application jenkins parameterized_trigger 2.22 Yes
Application jenkins parameterized_trigger 2.23 Yes
Application jenkins parameterized_trigger 2.24 Yes
Application jenkins parameterized_trigger 2.25 Yes
Application jenkins parameterized_trigger 2.26 Yes
Application jenkins parameterized_trigger 2.27 Yes
Application jenkins parameterized_trigger 2.28 Yes
Application jenkins parameterized_trigger 2.29 Yes
Application jenkins parameterized_trigger 2.30 Yes
Application jenkins parameterized_trigger 2.31 Yes
Application jenkins parameterized_trigger 2.32 Yes
Application jenkins parameterized_trigger 2.33 Yes
Application jenkins parameterized_trigger 2.34 Yes

References