CVE-2017-1000503 describes a race condition in Jenkins versions 2.81 through 2.94 during startup. This flaw could prevent the setup wizard from initializing correctly, leading to multiple security settings not being applied to their default strict values. The vulnerability has a CVSS score of 8.1 (HIGH), indicating a high potential for impact on confidentiality, integrity, and availability, with a network attack vector and high attack complexity. There is currently no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.81, <= 2.94CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:* | ||
2.89.1CPE matchmatch criteria | cpe:2.3:a:jenkins:jenkins:2.89.1:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.