PT-2018-7135 · Cloudbees+1 · Jenkins

Publicado

2018-05-22

·

Atualizado

2022-05-13

·

CVE-2017-2609

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Jenkins versions prior to 2.44 Jenkins version 2.32.2
Description: The issue concerns an information disclosure vulnerability in search suggestions. The autocomplete feature on the search box discloses the names of the views in its suggestions, including the ones for which the current user does not have access to.
Recommendations: For Jenkins versions prior to 2.44, update to version 2.44 or later to resolve the issue. For Jenkins version 2.32.2, update to a version later than 2.32.2 to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-2609
GHSA-V222-W2MW-XJC6

Produtos afetados

Jenkins