The remote API in Jenkins 2.73.1 and earlier, 2.83 and earlier at /computer/(agent-name)/api showed information about tasks (typically builds) currently running on that agent. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API now only shows information about accessible tasks.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-01-26T02:00:00
Updated: 2024-08-05T22:00:41.546Z
Reserved: 2017-11-29T00:00:00
Link: CVE-2017-1000398
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-01-26T02:29:01.047
Modified: 2024-11-21T03:04:38.477
Link: CVE-2017-1000398
Redhat