{"id":"CVE-2017-1000085","aliases":["GHSA-hrwc-pqfm-g6qf"],"url":"https://o3.security/vulnerability/CVE-2017-1000085","summary":"Jenkins Subversion Plugin Cross-Site Request Forgery vulnerability","details":"Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list of tags). This functionality improperly checked permissions, allowing any user with Item/Build permission (but not Item/Configure) to connect to any web server or Subversion server and send credentials with a known ID, thereby possibly capturing them. Additionally, this functionality did not require POST requests be used, thereby allowing the above to be performed without direct access to Jenkins via Cross-Site Request Forgery attacks.","published":"2017-10-05T01:29:03.540Z","modified":"2026-07-08T11:47:26.771029Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"},"epss":{"score":0.01031,"percentile":0.61136,"asOf":"2026-08-22"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.jenkins-ci.plugins:subversion","fixedVersion":"2.9"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/99574"},{"type":"ADVISORY","url":"https://jenkins.io/security/advisory/2017-07-10/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T11:47:26.771029Z"}}