Back

MEDIUM

jenkins-plugin-pipeline-build-step: Missing check of Item/Build permission (SECURITY-433)

Published Oct 4, 2017

Description

Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.

Affected products

Remediation

Red Hat statement

This issue affects the versions of jenkins-plugin-pipeline-build-step as shipped with Red Hat OpenShift Enterprise 3. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 4, 2017
Updated Aug 5, 2024
Reserved Jul 13, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jul 10, 2017
GHSA-8JX9-7J5M-79X4