Red Hat Bugzilla – Bug 1482094
CVE-2017-1000108 jenkins-plugin-pipeline-input-step: Input Step Plugin allows users with read access to interact with the step by default
Last modified: 2017-09-08 07:46:07 EDT
The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now users are required to have the Item/Build permission by default. External References: https://jenkins.io/security/advisory/2017-08-07/
Statement: Deferred (Low security impact) ======================================= This issue affects the versions of jenkins-plugin-script-security as shipped with Red Hat OpenShift Enterprise. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.