CVE-2017-1000396 affects Jenkins versions 2.73.1 and earlier, and 2.83 and earlier, due to a bundled vulnerable version of the commons-httpclient library (CVE-2012-6153). This vulnerability allows for man-in-the-middle attacks by incorrectly verifying SSL certificates, impacting the confidentiality and integrity of communications. Rated as MEDIUM severity (CVSS 5.9), it requires no user interaction and has high impact potential on integrity, though attack complexity is high. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.73.1CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* | ||
<= 2.83CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.