CVE-2017-2611: Jenkins

Medium severity, CVSS 4.3. EPSS: 2% chance of exploitation in the next 30 days.

Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jenkins to trigger these background processes (that are otherwise performed daily), possibly causing additional load on Jenkins master and agents.

Affected products

  • Jenkins Jenkins: before 2.32.2 (fixed in 2.32.2); before 2.44 (fixed in 2.44)
  • Red Hat Openshift: version 2.0 only; version 3.0 only

Published 2018-05-08. Last modified 2026-06-17.