vulnerability
Jenkins Advisory 2017-10-11: CVE-2017-1000398: "Computer" remote API disclosed information about inaccessible jobs
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:N/AC:L/Au:S/C:P/I:N/A:N) | Nov 20, 2017 | Nov 20, 2017 | Aug 11, 2025 |
Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
Nov 20, 2017
Added
Nov 20, 2017
Modified
Aug 11, 2025
Description
The remote API in Jenkins 2.73.1 and earlier, 2.83 and earlier at /computer/(agent-name)/api showed information about tasks (typically builds) currently running on that agent. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API now only shows information about accessible tasks.
Solutions
jenkins-lts-upgrade-2_73_2jenkins-upgrade-2_84
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.