CVE-2017-1000362

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-1000362
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000362.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-1000362
Aliases
Published
2017-07-17T13:18:18Z
Modified
2024-09-03T01:35:12.110748Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINSHOME with a new key. It also created a backup directory with all old secrets, and the key used to encrypt them. These backups were world-readable and not removed afterwards. Jenkins now deletes the backup directory, if present. Upgrading from before 1.498 will no longer create a backup directory. Administrators relying on file access permissions in their manually created backups are advised to check them for the directory $JENKINSHOME/jenkins.security.RekeySecretAdminMonitor/backups, and delete it if present.

References

Affected packages

Git / github.com/jenkinsci/jenkins

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/jenkins
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

1.*

1.324-rc
1.325-rc
1.327-rc
1.328-rc

Other

hudson-1_387
hudson-1_388
hudson-1_389
hudson-1_390
hudson-1_391
hudson-1_392
hudson-1_393
hudson-1_394
hudson-1_395
jenkins-1_396
jenkins-1_397
jenkins-1_398
jenkins-1_399
jenkins-1_400
jenkins-1_401
jenkins-1_402
jenkins-1_403
jenkins-1_404
jenkins-1_405
jenkins-1_406
jenkins-1_407
jenkins-1_408
jenkins-1_409
jenkins-1_410
jenkins-1_411
jenkins-1_412
jenkins-1_413
jenkins-1_414
jenkins-1_415

jenkins-1.*

jenkins-1.416
jenkins-1.417
jenkins-1.418
jenkins-1.419
jenkins-1.420
jenkins-1.421
jenkins-1.422
jenkins-1.423
jenkins-1.424
jenkins-1.425
jenkins-1.426
jenkins-1.427
jenkins-1.428
jenkins-1.429
jenkins-1.430
jenkins-1.431
jenkins-1.432
jenkins-1.433
jenkins-1.434
jenkins-1.435
jenkins-1.436
jenkins-1.437
jenkins-1.438
jenkins-1.439
jenkins-1.440
jenkins-1.441
jenkins-1.442
jenkins-1.443
jenkins-1.444
jenkins-1.445
jenkins-1.446
jenkins-1.447
jenkins-1.448
jenkins-1.449
jenkins-1.450
jenkins-1.451
jenkins-1.452
jenkins-1.453
jenkins-1.454
jenkins-1.455
jenkins-1.456
jenkins-1.457
jenkins-1.458
jenkins-1.459
jenkins-1.460
jenkins-1.461
jenkins-1.462
jenkins-1.463
jenkins-1.464
jenkins-1.465
jenkins-1.466
jenkins-1.467
jenkins-1.468
jenkins-1.469
jenkins-1.470
jenkins-1.471
jenkins-1.472
jenkins-1.473
jenkins-1.474
jenkins-1.475
jenkins-1.477
jenkins-1.478
jenkins-1.479
jenkins-1.480
jenkins-1.481
jenkins-1.482
jenkins-1.483
jenkins-1.484
jenkins-1.485
jenkins-1.486
jenkins-1.487
jenkins-1.488
jenkins-1.489
jenkins-1.490
jenkins-1.491
jenkins-1.492
jenkins-1.493
jenkins-1.494
jenkins-1.495
jenkins-1.496
jenkins-1.497
jenkins-1.498

prototype-1.*

prototype-1.5.1.1
prototype-1.7