CVE-2017-2599: Jenkins
Medium severity, CVSS 5.4. EPSS: 1.1% chance of exploitation in the next 30 days.
Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).
Affected products
- Jenkins Jenkins: before 2.32.2 (fixed in 2.32.2); before 2.44 (fixed in 2.44)
Published 2018-04-11. Last modified 2026-06-17.