CVE-2017-1000084

Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
jenkinsparameterized_trigger
1.0
jenkinsparameterized_trigger
1.1
jenkinsparameterized_trigger
1.2
jenkinsparameterized_trigger
1.3
jenkinsparameterized_trigger
1.4
jenkinsparameterized_trigger
1.5
jenkinsparameterized_trigger
1.6
jenkinsparameterized_trigger
2.0
jenkinsparameterized_trigger
2.1
jenkinsparameterized_trigger
2.2
jenkinsparameterized_trigger
2.3
jenkinsparameterized_trigger
2.4
jenkinsparameterized_trigger
2.5
jenkinsparameterized_trigger
2.6
jenkinsparameterized_trigger
2.7
jenkinsparameterized_trigger
2.8
jenkinsparameterized_trigger
2.9
jenkinsparameterized_trigger
2.10
jenkinsparameterized_trigger
2.11
jenkinsparameterized_trigger
2.12
jenkinsparameterized_trigger
2.13
jenkinsparameterized_trigger
2.14
jenkinsparameterized_trigger
2.15
jenkinsparameterized_trigger
2.16
jenkinsparameterized_trigger
2.17
jenkinsparameterized_trigger
2.18
jenkinsparameterized_trigger
2.19
jenkinsparameterized_trigger
2.20
jenkinsparameterized_trigger
2.21
jenkinsparameterized_trigger
2.22
jenkinsparameterized_trigger
2.23
jenkinsparameterized_trigger
2.24
jenkinsparameterized_trigger
2.25
jenkinsparameterized_trigger
2.26
jenkinsparameterized_trigger
2.27
jenkinsparameterized_trigger
2.28
jenkinsparameterized_trigger
2.29
jenkinsparameterized_trigger
2.30
jenkinsparameterized_trigger
2.31
jenkinsparameterized_trigger
2.32
jenkinsparameterized_trigger
2.33
jenkinsparameterized_trigger
2.34
𝑥
= Vulnerable software versions