Описание
Jenkins XPath Configuration Viewer Plugin Missing Authorization vulnerability
Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier does not perform permission checks in several HTTP endpoints.
This allows attackers with Overall/Read permission to create and delete XPath expressions.
Additionally, these HTTP endpoints do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.
As of publication of this advisory, there is no fix.
Пакеты
Наименование
org.jenkins-ci.plugins:xpath-config-viewer
maven
Затронутые версииВерсия исправления
<= 1.1.1
Отсутствует
Связанные уязвимости
CVSS3: 4.3
nvd
больше 3 лет назад
A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to create and delete XPath expressions.