{"id":"CVE-2017-1000356","aliases":["GHSA-85wq-pqhp-hmq6"],"url":"https://o3.security/vulnerability/CVE-2017-1000356","summary":"Cross-Site Request Forgery in Jenkins","details":"Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an issue in the Jenkins user database authentication realm: create an account if signup is enabled; or create an account if the victim is an administrator, possibly deleting the existing default admin user in the process and allowing a wide variety of impacts.","published":"2018-01-29T17:29:00.363Z","modified":"2026-07-08T11:49:01.406761Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.06957,"percentile":0.93563,"asOf":"2026-08-18"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.jenkins-ci.main:jenkins-core","fixedVersion":"2.57"},{"ecosystem":"Maven","name":"org.jenkins-ci.main:jenkins-core","fixedVersion":"2.46.2"}],"fix":{"url":"https://github.com/jenkinsci/jenkins/commit/23f4809e6c10a221e9d67f2e841536845387b42d","label":"jenkinsci/jenkins@23f4809"},"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/98062"},{"type":"ADVISORY","url":"https://jenkins.io/security/advisory/2017-04-26/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-1000356"},{"type":"WEB","url":"https://github.com/jenkinsci/jenkins/commit/23f4809e6c10a221e9d67f2e841536845387b42d"},{"type":"WEB","url":"https://github.com/jenkinsci/jenkins/commit/3c5e5ca63d9a1ac1c4087682dc0d426625eafed8"},{"type":"WEB","url":"https://github.com/jenkinsci/jenkins/commit/e69c28e44dae41322112471e1c80f840bde314d4"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/jenkins"},{"type":"WEB","url":"https://jenkins.io/security/advisory/2017-04-26"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T11:49:01.406761Z"}}