Upstream information
Description
Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to 'people', which encompasses actual user accounts, as well as users appearing in SCM, in directories corresponding to the user ID on disk. These directories used the user ID for their name without additional escaping, potentially resulting in problems like overwriting of unrelated configuration files.SUSE information
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having important severity.
National Vulnerability Database | |
---|---|
Base Score | 4.9 |
Vector | AV:N/AC:M/Au:S/C:N/I:P/A:P |
Access Vector | Network |
Access Complexity | Medium |
Authentication | Single |
Confidentiality Impact | None |
Integrity Impact | Partial |
Availability Impact | Partial |
National Vulnerability Database | |
---|---|
Base Score | 7.3 |
Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H |
Attack Vector | Network |
Attack Complexity | Low |
Privileges Required | Low |
User Interaction | Required |
Scope | Unchanged |
Confidentiality Impact | None |
Integrity Impact | High |
Availability Impact | High |
CVSSv3 Version | 3 |
SUSE Timeline for this CVE
CVE page created: Sat Nov 18 10:21:27 2017CVE page last modified: Mon Sep 16 15:27:06 2024