Description
Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3197 | Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins. |
Github GHSA |
GHSA-8jx9-7j5m-79x4 | Jenkins Build Step Plugin fails to check Item/Build permission |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T21:53:06.250Z
Reserved: 2017-07-13T00:00:00.000Z
Link: CVE-2017-1000089
No data.
Status : Modified
Published: 2017-10-05T01:29:03.667
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-1000089
OpenCVE Enrichment
No data.
EUVD
Github GHSA