Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.
CVSS Details
- CVSS 3.0 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade rubygem-fluent-plugin-kubernetes_metadata_filterUpgrade kibanaUpgrade rubygem-exconUpgrade rubygem-cool.ioUpgrade fluentdUpgrade rubygem-fluent-plugin-viaq_data_modelUpgrade jenkins-2-pluginsUpgrade atomic-openshiftUpgrade rubygem-faradayUpgrade rubygem-i18nUpgrade rubygem-systemd-journal | May 7, 2019 | Jul 10, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub