CVE-2017-1000243: Jenkins Favorite Plugin

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites

Affected products

  • Jenkins Favorite Plugin: up to and including 2.1.4

Published 2017-11-01. Last modified 2026-06-17.