CVE-2017-1000388: Jenkins Dependency Graph Viewer
Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.
Jenkins Dependency Graph Viewer plugin 0.12 and earlier did not perform permission checks for the API endpoint that modifies the dependency graph, allowing anyone with Overall/Read permission to modify this data.
Affected products
- Jenkins Dependency Graph Viewer: up to and including 0.12
Published 2018-01-26. Last modified 2026-06-17.