Race condition in Jenkins - CVE-2017-1000503

 

Race condition in Jenkins - CVE-2017-1000503

Published: January 25, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37590
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2017-1000503
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Jenkins
Affected software:
Jenkins

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1 startup could result in the wrong order of execution of commands during initialization. This could in rare cases result in failure to initialize the setup wizard on the first startup. This resulted in multiple security-related settings not being set to their usual strict default.


How to mitigate CVE-2017-1000503

Install update from vendor's website.

Sources