CVE-2017-1000108: Jenkins Pipeline-Input-Step
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item/Build permission instead.
Affected products
- Jenkins Pipeline-Input-Step: version 2.0 only; version 2.1 only; version 2.2 only; version 2.3 only; version 2.4 only; version 2.5 only; …
Published 2017-10-05. Last modified 2026-06-17.