Логотип exploitDog
bind:CVE-2017-1000399
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-1000399

Количество 5

Количество 5

ubuntu логотип

CVE-2017-1000399

около 8 лет назад

The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/item/(ID)/api showed information about tasks in the queue (typically builds waiting to start). This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API endpoint is now only available for tasks that the current user has access to.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2017-1000399

больше 8 лет назад

The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/item/(ID)/api showed information about tasks in the queue (typically builds waiting to start). This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API endpoint is now only available for tasks that the current user has access to.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2017-1000399

около 8 лет назад

The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/item/(ID)/api showed information about tasks in the queue (typically builds waiting to start). This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API endpoint is now only available for tasks that the current user has access to.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2017-1000399

около 8 лет назад

The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/ ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-g78x-xmv8-23xp

больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-1000399

The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/item/(ID)/api showed information about tasks in the queue (typically builds waiting to start). This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API endpoint is now only available for tasks that the current user has access to.

CVSS3: 4.3
0%
Низкий
около 8 лет назад
redhat логотип
CVE-2017-1000399

The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/item/(ID)/api showed information about tasks in the queue (typically builds waiting to start). This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API endpoint is now only available for tasks that the current user has access to.

CVSS3: 4.3
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-1000399

The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/item/(ID)/api showed information about tasks in the queue (typically builds waiting to start). This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API endpoint is now only available for tasks that the current user has access to.

CVSS3: 4.3
0%
Низкий
около 8 лет назад
debian логотип
CVE-2017-1000399

The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/ ...

CVSS3: 4.3
0%
Низкий
около 8 лет назад
github логотип
GHSA-g78x-xmv8-23xp

Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу