PT-2017-10811 · Jenkins · Blue Ocean+1

Cliff Meyers

·

Publicado

2017-10-04

·

Atualizado

2022-05-13

·

CVE-2017-1000106

CVSS v3.1

8.5

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Blue Ocean (affected versions not specified)
Description The issue concerns the SCM content REST API in Blue Ocean, which does not properly check user authentication or credentials. This allows users with read access to a GitHub organization folder to create arbitrary commits in the corresponding repositories using the creator's GitHub credentials. Additionally, these users can read arbitrary file contents from the repositories if a branch contains a Jenkinsfile, by providing the organization folder name, repository name, branch name, and file name.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-1000106
GHSA-QGJQ-M78X-4GM8

Produtos afetados

Blue Ocean
Jenkins