Medium severity5.4NVD Advisory· Published Apr 11, 2018· Updated Jun 17, 2026
CVE-2017-2599
CVE-2017-2599
Description
Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.main:jenkins-coreMaven | < 2.32.2 | 2.32.2 |
org.jenkins-ci.main:jenkins-coreMaven | >= 2.34, < 2.44 | 2.44 |
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/jenkinsci/jenkins/commit/4ed5c850b6855ab064a66d02fb338f366853ce89nvdPatchThird Party AdvisoryWEB
- www.securityfocus.com/bid/95949nvdThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-7r4h-2h23-6jq9ghsaADVISORY
- jenkins.io/security/advisory/2017-02-01/nvdVendor Advisory
- nvd.nist.gov/vuln/detail/CVE-2017-2599ghsaADVISORY
- jenkins.io/security/advisory/2017-02-01ghsaWEB
News mentions
0No linked articles in our index yet.