Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2q8v-439j-6p77

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

Jenkins Exclusion Plugin allows Access to Resource Locks

The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.

Пакеты

Наименование

org.jenkins-ci.plugins:exclusion

maven
Затронутые версииВерсия исправления

< 0.9

0.9

EPSS

Процентиль: 60%
0.00403
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-284

Связанные уязвимости

ubuntu
около 12 лет назад

The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.

redhat
около 12 лет назад

The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.

nvd
около 12 лет назад

The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.

debian
около 12 лет назад

The Exclusion plugin before 0.9 for Jenkins does not properly prevent ...

EPSS

Процентиль: 60%
0.00403
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-284