HIGH
jenkins: Unsafe use of user names as directory names
Published Jan 26, 2018
7.3
HIGHCVSS 3.0
EPSS 1.50%
Description
Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to 'people', which encompasses actual user accounts, as well as users appearing in SCM, in directories corresponding to the user ID on disk. These directories used the user ID for their name without additional escaping, potentially resulting in problems like overwriting of unrelated configuration files.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://www.securityfocus.com/bid/101773 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2017-1000391 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1516788 Issue Tracking
- https://github.com/advisories/GHSA-wfj3-535m-p6fx Advisory
- https://github.com/jenkinsci/jenkins/commit/566a8ddb885f0bef9bc848e60455c0aabbf0c1d3
- https://jenkins.io/security/advisory/2017-11-08/ x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000391
- https://www.cve.org/CVERecord?id=CVE-2017-1000391
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/101773 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2017-1000391 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1516788 | Issue Tracking | |
| https://github.com/advisories/GHSA-wfj3-535m-p6fx | Advisory | |
| https://github.com/jenkinsci/jenkins/commit/566a8ddb885f0bef9bc848e60455c0aabbf0c1d3 | ||
| https://jenkins.io/security/advisory/2017-11-08/ | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-1000391 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-1000391 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 26, 2018
Updated Aug 5, 2024
Reserved Nov 29, 2017
Link CVE-2017-1000391
CISA Vulnrichment
GHSA-WFJ3-535M-P6FX Updated n/a