~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2017-2613

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2017-2613
2
 
PublicDate: 2018-05-15
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2613
5
 
 https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2017-02-01
6
 
Description:
7
 
 jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF
8
 
 using GET by admins. While this user record was only retained until restart
9
 
 in most cases, administrators' web browsers could be manipulated to create
10
 
 a large number of user records (SECURITY-406).
11
 
 
12
 
 Accessing these URLs now no longer results in a user record getting
13
 
 created, Jenkins will respond with 404 Not Found if no such user
14
 
 exists. When using the internal Jenkins user database, new users can
15
 
 be created via Manage Jenkins » Manage Users.
16
 
Ubuntu-Description:
17
 
Notes:
18
 
Bugs:
19
 
Priority: medium
20
 
Discovered-by: Jean Marsault
21
 
Assigned-to:
22
 
 
23
 
Patches_jenkins:
24
 
upstream_jenkins: released (2.44, 2.32.2)
25
 
precise_jenkins: ignored (reached end-of-life)
26
 
precise/esm_jenkins: DNE (precise was needed)
27
 
trusty_jenkins: DNE
28
 
vivid/stable-phone-overlay_jenkins: DNE
29
 
vivid/ubuntu-core_jenkins: DNE
30
 
xenial_jenkins: DNE
31
 
yakkety_jenkins: DNE
32
 
zesty_jenkins: DNE
33
 
devel_jenkins: DNE