Files
CVEs-PoC/2017/CVE-2017-2600.md
T
2025-09-29 21:09:30 +02:00

19 lines
778 B
Markdown

### [CVE-2017-2600](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2600)
![](https://img.shields.io/static/v1?label=Product&message=jenkins&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=jenkins%202.32.2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=jenkins%202.44%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-325&color=brightgreen)
### Description
In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. These included system configuration and runtime information of these nodes (SECURITY-343).
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/ARPSyndicate/cvemon