Описание
Missing permission check in Jenkins Favorite Plugin
Jenkins Favorite Plugin up to and including 2.1.0 does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
Пакеты
Наименование
org.jvnet.hudson.plugins:favorite
maven
Затронутые версииВерсия исправления
< 2.3.0
2.3.0
Связанные уязвимости
CVSS3: 4.3
redhat
больше 8 лет назад
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
CVSS3: 4.3
nvd
около 8 лет назад
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites