SCA: security update for org.jenkins-ci.main:jenkins-core (GHSA-g78x-xmv8-23xp)

medium Tenable Self-Hosted Container Security Plugin ID 414960

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/item/(ID)/api showed information
about tasks in the queue (typically builds waiting to start). This included information about tasks that
the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been
fixed, and the API endpoint is now only available for tasks that the current user has access to.
(CVE-2017-1000399)

See Also

https://github.com/advisories/GHSA-g78x-xmv8-23xp

Plugin Details

Severity: Medium

ID: 414960

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2017-1000399

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/14/2022

Vulnerability Publication Date: 10/11/2017

Reference Information

CVE: CVE-2017-1000399

BID: 104305

cwe: CWE-200