CVE-2017-1000089 describes a vulnerability in the Jenkins Pipeline: Build Step Plugin where it failed to properly check build authentication. This allowed an attacker to trigger any other project within Jenkins, bypassing intended permission controls. Rated as Medium severity (CVSS 5.3), this vulnerability has a network attack vector with low complexity, potentially leading to unauthorized information disclosure or modification (CWE-276). There is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.5CPE matchmatch criteria | cpe:2.3:a:jenkins:pipeline\:_build_step:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.