VYPR
Medium severity4.3NVD Advisory· Published Oct 5, 2017· Updated May 13, 2026

CVE-2017-1000087

CVE-2017-1000087

Description

GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those could be used as part of an attack to capture the credentials using another vulnerability.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:github-branch-sourceMaven
< 2.2.0-alpha-12.2.0-alpha-1

Affected products

40
  • cpe:2.3:a:jenkins:github_branch_source:0.1:beta-1:*:*:*:jenkins:*:*+ 39 more
    • cpe:2.3:a:jenkins:github_branch_source:0.1:beta-1:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:0.1:beta-2:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:0.1:beta-3:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:0.1:beta-4:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:1.0:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:1.10:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:1.1:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:1.2:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:1.3:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:1.4:beta-1:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:1.4:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:1.5:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:1.6:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:1.7:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:1.8.1:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:1.8:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:1.9:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.0:beta-1:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.0:beta-2:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.0:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.1:beta-1:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.1:beta-2:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.1:beta-3:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.1:beta-4:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.1:beta-5:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.1:beta-6:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.1:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.2:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.3:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.4:beta-1:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.4:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.5:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.0.6:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.2.0:alpha-1:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.2.0:alpha-2:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.2.0:alpha-3:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.2.0:alpha-4:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.2.0:beta-1:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:2.2.0:*:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:github_branch_source:*:*:*:*:*:jenkins:*:*range: <=2.0.7

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.