CVE-2017-2600
15.05.2018, 20:29
In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. These included system configuration and runtime information of these nodes (SECURITY-343).Enginsight
Vendor | Product | Version |
---|---|---|
jenkins | jenkins | 𝑥 < 2.44 |
jenkins | jenkins | 𝑥 < 2.32.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-325 - Missing Cryptographic StepThe product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
References