Show plain JSON{"acknowledgement": "Red Hat would like to thank the Jenkins project for reporting this issue.", "affected_release": [{"advisory": "RHBA-2017:2642", "cpe": "cpe:/a:redhat:openshift:3.6::el7", "package": "atomic-openshift-0:3.6.173.0.21-1.git.0.f95b0e7.el7", "product_name": "Red Hat OpenShift Container Platform 3.6", "release_date": "2017-09-08T00:00:00Z"}, {"advisory": "RHBA-2017:2642", "cpe": "cpe:/a:redhat:openshift:3.6::el7", "package": "fluentd-0:0.12.39-2.el7", "product_name": "Red Hat OpenShift Container Platform 3.6", "release_date": "2017-09-08T00:00:00Z"}, {"advisory": "RHBA-2017:2642", "cpe": "cpe:/a:redhat:openshift:3.6::el7", "package": "jenkins-2-plugins-0:3.7.1502412812-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.6", "release_date": "2017-09-08T00:00:00Z"}, {"advisory": "RHBA-2017:2642", "cpe": "cpe:/a:redhat:openshift:3.6::el7", "package": "kibana-0:4.6.4-3.el7", "product_name": "Red Hat OpenShift Container Platform 3.6", "release_date": "2017-09-08T00:00:00Z"}, {"advisory": "RHBA-2017:2642", "cpe": "cpe:/a:redhat:openshift:3.6::el7", "package": "rubygem-cool.io-0:1.5.1-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.6", "release_date": "2017-09-08T00:00:00Z"}, {"advisory": "RHBA-2017:2642", "cpe": "cpe:/a:redhat:openshift:3.6::el7", "package": "rubygem-excon-0:0.58.0-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.6", "release_date": "2017-09-08T00:00:00Z"}, {"advisory": "RHBA-2017:2642", "cpe": "cpe:/a:redhat:openshift:3.6::el7", "package": "rubygem-faraday-0:0.13.0-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.6", "release_date": "2017-09-08T00:00:00Z"}, {"advisory": "RHBA-2017:2642", "cpe": "cpe:/a:redhat:openshift:3.6::el7", "package": "rubygem-fluent-plugin-kubernetes_metadata_filter-0:0.29.0-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.6", "release_date": "2017-09-08T00:00:00Z"}, {"advisory": "RHBA-2017:2642", "cpe": "cpe:/a:redhat:openshift:3.6::el7", "package": "rubygem-fluent-plugin-viaq_data_model-0:0.0.5-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.6", "release_date": "2017-09-08T00:00:00Z"}, {"advisory": "RHBA-2017:2642", "cpe": "cpe:/a:redhat:openshift:3.6::el7", "package": "rubygem-i18n-0:0.8.6-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.6", "release_date": "2017-09-08T00:00:00Z"}, {"advisory": "RHBA-2017:2642", "cpe": "cpe:/a:redhat:openshift:3.6::el7", "package": "rubygem-systemd-journal-0:1.3.0-1.el7", "product_name": "Red Hat OpenShift Container Platform 3.6", "release_date": "2017-09-08T00:00:00Z"}], "bugzilla": {"description": "jenkins-plugin-pipeline-build-step: Missing check of Item/Build permission (SECURITY-433)", "id": "1471050", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1471050"}, "csaw": false, "cvss3": {"cvss3_base_score": "3.7", "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N", "status": "verified"}, "cwe": "CWE-287", "details": ["Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.", "The jenkins-plugin-pipeline-build-step fails to check permissions correctly allowing attackers with access to it to specify the triggering of any other project in Jenkins. This potentially gives an attacker access to projects they should not have access to."], "name": "CVE-2017-1000089", "package_state": [{"cpe": "cpe:/a:redhat:openshift:3", "fix_state": "Will not fix", "package_name": "jenkins-plugin-pipeline-build-step", "product_name": "Red Hat OpenShift Enterprise 3"}], "public_date": "2017-07-10T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2017-1000089\nhttps://nvd.nist.gov/vuln/detail/CVE-2017-1000089\nhttps://jenkins.io/security/advisory/2017-07-10/"], "statement": "This issue affects the versions of jenkins-plugin-pipeline-build-step as shipped with Red Hat OpenShift Enterprise 3. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.", "threat_severity": "Low"}