CVE-2017-2600

Description

In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. These included system configuration and runtime information of these nodes (SECURITY-343).

Risk Information

Base Score
4.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.034

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Jenkins-Core 2.32.2Windows
Multiple vulnerabilities are fixed in Jenkins-Core 2.44Windows
Multiple vulnerabilities are fixed in Jenkins-Core for Linux 2.32.2Linux
Multiple vulnerabilities are fixed in Jenkins-Core for Linux 2.44Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234