CVE-2017-1000108

The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item/Build permission instead.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
VendorProductVersion
jenkinspipeline-input-step
2.0
jenkinspipeline-input-step
2.1
jenkinspipeline-input-step
2.2
jenkinspipeline-input-step
2.3
jenkinspipeline-input-step
2.4
jenkinspipeline-input-step
2.5
jenkinspipeline-input-step
2.6
jenkinspipeline-input-step
2.7
𝑥
= Vulnerable software versions