← back
CVE-2017-2599

CVE-2017-2599

CVSS 5.4 MEDIUMEPSS 1.1%CWE-863
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 1.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
11 Apr 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected products
[UNKNOWN] · jenkins

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →