Medium severity4.3NVD Advisory· Published Jan 26, 2018· Updated Jun 17, 2026
CVE-2017-1000388
CVE-2017-1000388
Description
Jenkins Dependency Graph Viewer plugin 0.12 and earlier did not perform permission checks for the API endpoint that modifies the dependency graph, allowing anyone with Overall/Read permission to modify this data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:depgraph-viewMaven | < 0.13 | 0.13 |
Affected products
2- cpe:2.3:a:jenkins:dependency_graph_viewer:*:*:*:*:*:jenkins:*:*Range: <=0.12
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-vhh3-mvc4-hhq6ghsaADVISORY
- jenkins.io/security/advisory/2017-10-23/nvdVendor Advisory
- nvd.nist.gov/vuln/detail/CVE-2017-1000388ghsaADVISORY
- jenkins.io/security/advisory/2017-10-23ghsaWEB
News mentions
0No linked articles in our index yet.