CVE-2017-2600 Vulnerability Details

  /     /     /  

CVE-2017-2600 Metadata Quick Info

CVE Published: 15/05/2018 | CVE Updated: 05/08/2024 | CVE Year: 2017
Source: redhat | Vendor: [UNKNOWN] | Product: jenkins
Status : PUBLISHED

CVE-2017-2600 Description

In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. These included system configuration and runtime information of these nodes (SECURITY-343).

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-325
CWE Name: CWE-325
Source: [UNKNOWN]

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).