Description
The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item/Build permission instead.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4246 | The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item/Build permission instead. |
Github GHSA |
GHSA-hxpw-7x95-q38m | Jenkins Pipeline: Input Step Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T20:32:34.224Z
Reserved: 2017-10-03T00:00:00.000Z
Link: CVE-2017-1000108
No data.
Status : Modified
Published: 2017-10-05T01:29:04.337
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-1000108
OpenCVE Enrichment
No data.
EUVD
Github GHSA