Permission Misconfiguration in Jenkins Subversion Plugin
CVE-2017-1000085
6.5MEDIUM
Key Information:
- Vendor
Jenkins
- Status
- Vendor
- CVE Published:
- 4 October 2017
What is CVE-2017-1000085?
The Jenkins Subversion Plugin connects to a user-defined Subversion repository during form validation which can lead to improper permission checks. This vulnerability enables users with limited permissions (Item/Build) to access both web and Subversion servers, potentially exposing sensitive credentials due to the lack of required POST requests. Attackers could exploit this weakness via Cross-Site Request Forgery attacks, further compromising the integrity of the system.