Back

MEDIUM

jenkins: "Job" remote API disclosed information about inaccessible upstream/downstream jobs (SECURITY-617)

Published Jan 26, 2018

Description

The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream and downstream projects. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API now only lists upstream and downstream projects that the current user has access to.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 26, 2018
Updated Aug 5, 2024
Reserved Nov 29, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 11, 2017
GHSA-P8X8-P473-MMMV