{"id":"GHSA-hxpw-7x95-q38m","summary":"Jenkins Pipeline: Input Step Plugin","details":"The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item/Build permission instead.","aliases":["CVE-2017-1000108"],"modified":"2024-02-21T05:20:55.203867Z","published":"2022-05-17T00:29:01Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-12-12T21:03:30Z","nvd_published_at":"2017-10-05T01:29:00Z","cwe_ids":["CWE-200"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000108"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/pipeline-input-step-plugin"},{"type":"WEB","url":"https://jenkins.io/security/advisory/2017-08-07"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:pipeline-input-step","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/pipeline-input-step"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7"}]}],"versions":["2.0","2.1","2.2","2.3","2.4","2.5","2.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hxpw-7x95-q38m/GHSA-hxpw-7x95-q38m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}