Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2q8v-439j-6p77

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

Jenkins Exclusion Plugin allows Access to Resource Locks

The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.

Пакеты

Наименование

org.jenkins-ci.plugins:exclusion

maven
Затронутые версииВерсия исправления

< 0.9

0.9

EPSS

Процентиль: 64%
0.01147
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-284

Связанные уязвимости

ubuntu
больше 12 лет назад

The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.

redhat
почти 13 лет назад

The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.

nvd
больше 12 лет назад

The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.

debian
больше 12 лет назад

The Exclusion plugin before 0.9 for Jenkins does not properly prevent ...

EPSS

Процентиль: 64%
0.01147
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-284