CVE-2017-2604: Jenkins
Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not being consistently protected by permission checks (SECURITY-371).
Affected products
- Jenkins Jenkins: before 2.44 (fixed in 2.44); before 2.32.2 (fixed in 2.32.2)
Published 2018-05-15. Last modified 2026-06-17.