HIGH
jenkins: Race condition during startup can result in default security settings not being applied
Published Jan 24, 2018
8.8
HIGHCVSS 3.0
EPSS 1.15%
Description
A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1 startup could result in the wrong order of execution of commands during initialization. This could in rare cases result in failure to initialize the setup wizard on the first startup. This resulted in multiple security-related settings not being set to their usual strict default.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://access.redhat.com/security/cve/CVE-2017-1000503 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1539480 Issue Tracking
- https://github.com/advisories/GHSA-r5x3-2446-hrp7 Advisory
- https://github.com/jenkinsci/jenkins/commit/ccc374a7176d7704941fb494589790b7673efe2
- https://jenkins.io/security/advisory/2017-12-14 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000503
- https://www.cve.org/CVERecord?id=CVE-2017-1000503
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2017-1000503 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1539480 | Issue Tracking | |
| https://github.com/advisories/GHSA-r5x3-2446-hrp7 | Advisory | |
| https://github.com/jenkinsci/jenkins/commit/ccc374a7176d7704941fb494589790b7673efe2 | ||
| https://jenkins.io/security/advisory/2017-12-14 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-1000503 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-1000503 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 24, 2018
Updated Sep 16, 2024
Reserved Jan 24, 2018
Link CVE-2017-1000503
CISA Vulnrichment
GHSA-R5X3-2446-HRP7 Updated n/a