Description
The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing access to archived artifacts, Item/Read permission was sufficient.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4773 | The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing access to archived artifacts, Item/Read permission was sufficient. |
Github GHSA |
GHSA-phf8-3qgv-rg5q | Missing Authorization in Jenkins Blue Ocean Plugin |
References
| Link | Providers |
|---|---|
| https://jenkins.io/security/advisory/2017-08-07/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T22:01:35.795Z
Reserved: 2017-10-03T00:00:00.000Z
Link: CVE-2017-1000105
No data.
Status : Modified
Published: 2017-10-05T01:29:04.243
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-1000105
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA