CVE-2017-2602: Jenkins

Medium severity, CVSS 4.3. EPSS: 1.6% chance of exploitation in the next 30 days.

jenkins before versions 2.44, 2.32.2 is vulnerable to an improper blacklisting of the Pipeline metadata files in the agent-to-master security subsystem. This could allow metadata files to be written to by malicious agents (SECURITY-358).

Affected products

  • Jenkins Jenkins: before 2.32.2 (fixed in 2.32.2); before 2.44 (fixed in 2.44)

Published 2018-05-15. Last modified 2026-06-17.