Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1501817 - (CVE-2017-1000399) CVE-2017-1000399 jenkins: "Queue Item" remote API disclosed information about inaccessible jobs (SECURITY-618)
CVE-2017-1000399 jenkins: "Queue Item" remote API disclosed information about...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20171011,repor...
: Security
Depends On: 1558840 1501971 1558841
Blocks: 1501826
  Show dependency treegraph
 
Reported: 2017-10-13 05:21 EDT by Adam Mariš
Modified: 2018-06-29 18:29 EDT (History)
13 users (show)

See Also:
Fixed In Version: jenkins 2.73.2, jenkins 2.83
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Adam Mariš 2017-10-13 05:21:52 EDT
The remote API at /queue/item/(ID)/api showed information about tasks in the queue (typically builds waiting to start). This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Job/Read permission.

External References:

https://jenkins.io/security/advisory/2017-10-11/
Comment 1 Kurt Seifried 2017-10-13 11:34:16 EDT
Created jenkins tracking bugs for this issue:

Affects: openshift-1 [bug 1501971]
Comment 2 Jason Shepherd 2018-03-21 02:19:51 EDT
Created jenkins tracking bugs for this issue:

Affects: fedora-all [bug 1558840]
Comment 4 Jason Shepherd 2018-04-03 01:12:06 EDT
Openshift is now using Jenkins 2.89.2. Marking Enterprise and Online as not affected.

Note You need to log in before you can comment on or make changes to this bug.