VYPR
Medium severity5.3NVD Advisory· Published Oct 5, 2017· Updated May 13, 2026

CVE-2017-1000105

CVE-2017-1000105

Description

The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing access to archived artifacts, Item/Read permission was sufficient.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
io.jenkins.blueocean:blueoceanMaven
<= 1.2.4

Affected products

4
  • cpe:2.3:a:jenkins:blue_ocean:*:*:*:*:*:jenkins:*:*+ 3 more
    • cpe:2.3:a:jenkins:blue_ocean:*:*:*:*:*:jenkins:*:*range: <=1.1.5
    • cpe:2.3:a:jenkins:blue_ocean:1.2.0:beta-1:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:blue_ocean:1.2.0:beta-2:*:*:*:jenkins:*:*
    • cpe:2.3:a:jenkins:blue_ocean:1.2.0:beta-3:*:*:*:jenkins:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.