Medium severity4.3NVD Advisory· Published Nov 1, 2017· Updated Jun 17, 2026
CVE-2017-1000243
CVE-2017-1000243
Description
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jvnet.hudson.plugins:favoriteMaven | < 2.3.0 | 2.3.0 |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-268v-2qq7-84pfghsaADVISORY
- jenkins.io/security/advisory/2017-06-06/nvdVendor Advisory
- nvd.nist.gov/vuln/detail/CVE-2017-1000243ghsaADVISORY
- www.securityfocus.com/bid/101946nvdWEB
- jenkins.io/security/advisory/2017-06-06ghsaWEB
News mentions
0No linked articles in our index yet.