Vulnerability Details CVE-2017-1000087
GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those could be used as part of an attack to capture the credentials using another vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 4.7%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.0
Products affected by CVE-2017-1000087
-
cpe:2.3:a:jenkins:github_branch_source:0.1
-
cpe:2.3:a:jenkins:github_branch_source:1.0
-
cpe:2.3:a:jenkins:github_branch_source:1.1
-
cpe:2.3:a:jenkins:github_branch_source:1.10
-
cpe:2.3:a:jenkins:github_branch_source:1.2
-
cpe:2.3:a:jenkins:github_branch_source:1.3
-
cpe:2.3:a:jenkins:github_branch_source:1.4
-
cpe:2.3:a:jenkins:github_branch_source:1.5
-
cpe:2.3:a:jenkins:github_branch_source:1.6
-
cpe:2.3:a:jenkins:github_branch_source:1.7
-
cpe:2.3:a:jenkins:github_branch_source:1.8
-
cpe:2.3:a:jenkins:github_branch_source:1.8.1
-
cpe:2.3:a:jenkins:github_branch_source:1.9
-
cpe:2.3:a:jenkins:github_branch_source:2.0.0
-
cpe:2.3:a:jenkins:github_branch_source:2.0.1
-
cpe:2.3:a:jenkins:github_branch_source:2.0.2
-
cpe:2.3:a:jenkins:github_branch_source:2.0.3
-
cpe:2.3:a:jenkins:github_branch_source:2.0.4
-
cpe:2.3:a:jenkins:github_branch_source:2.0.5
-
cpe:2.3:a:jenkins:github_branch_source:2.0.6
-
cpe:2.3:a:jenkins:github_branch_source:2.0.7
-
cpe:2.3:a:jenkins:github_branch_source:2.2.0