CVE-2017-1000391

Description

Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to people, which encompasses actual user accounts, as well as users appearing in SCM, in directories corresponding to the user ID on disk. These directories used the user ID for their name without additional escaping, potentially resulting in problems like overwriting of unrelated configuration files.

Risk Information

Base Score
7.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
EPSS Score
Exploitation Probability
0.202

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Jenkins 2.88Windows
Vulnerabilities CVE-2017-1000392,CVE-2017-1000391 are fixed in Jenkins-Core 2.73.3Windows
Vulnerabilities CVE-2017-1000392,CVE-2017-1000391 are fixed in Jenkins-Core 2.89Windows
Multiple vulnerabilities affected in Jenkins 2.88 (For Ubuntu)Linux
Multiple vulnerabilities affected in Jenkins 2.88 (For Debian)Linux
Multiple vulnerabilities affected in Jenkins 2.88 (For Centos)Linux
Multiple vulnerabilities affected in Jenkins 2.88 (For RedHat)Linux
Multiple vulnerabilities affected in Jenkins 2.88 (For Suse)Linux
Vulnerabilities CVE-2017-1000392,CVE-2017-1000391 are fixed in Jenkins-Core for Linux 2.73.3Linux
Vulnerabilities CVE-2017-1000392,CVE-2017-1000391 are fixed in Jenkins-Core for Linux 2.89Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234