High severity7.3NVD Advisory· Published Jan 26, 2018· Updated Jun 17, 2026
CVE-2017-1000391
CVE-2017-1000391
Description
Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to 'people', which encompasses actual user accounts, as well as users appearing in SCM, in directories corresponding to the user ID on disk. These directories used the user ID for their name without additional escaping, potentially resulting in problems like overwriting of unrelated configuration files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.main:jenkins-coreMaven | < 2.73.3 | 2.73.3 |
org.jenkins-ci.main:jenkins-coreMaven | >= 2.74, < 2.89 | 2.89 |
Affected products
3cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*+ 1 more
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*range: <=2.88
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*range: <=2.73.2
Patches
Vulnerability mechanics
References
6- www.securityfocus.com/bid/101773nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-wfj3-535m-p6fxghsaADVISORY
- jenkins.io/security/advisory/2017-11-08/nvdVendor Advisory
- nvd.nist.gov/vuln/detail/CVE-2017-1000391ghsaADVISORY
- github.com/jenkinsci/jenkins/commit/566a8ddb885f0bef9bc848e60455c0aabbf0c1d3ghsaWEB
- jenkins.io/security/advisory/2017-11-08ghsaWEB
News mentions
0No linked articles in our index yet.