Vulnerability Description
Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use to authenticate with a Docker Registry. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those could be used as part of an attack to capture the credentials using another vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Docker Commons | <= 1.9 |
Related Weaknesses (CWE)
References
- https://jenkins.io/security/advisory/2017-07-10/Vendor Advisory
- https://jenkins.io/security/advisory/2017-07-10/Vendor Advisory
FAQ
What is CVE-2017-1000094?
CVE-2017-1000094 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use to authenticate with a Docker Registry. This functionality did ...
How severe is CVE-2017-1000094?
CVE-2017-1000094 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-1000094?
Check the references section above for vendor advisories and patch information. Affected products include: Jenkins Docker Commons.