ZeroHour

CVE-2017-1000108

CVSS 3.0
7.5 high
EPSS
1%p65
Published
()
Modified
Description

The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item/Build permission instead.

Vendors
jenkins
Products
pipeline-input-step
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.