CVE-2017-1000105
05.10.2017, 01:29
The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing access to archived artifacts, Item/Read permission was sufficient.Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | blue_ocean | 𝑥 ≤ 1.1.5 |
jenkins | blue_ocean | 1.2.0:beta-1 |
jenkins | blue_ocean | 1.2.0:beta-2 |
jenkins | blue_ocean | 1.2.0:beta-3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration