Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3jp6-q9cg-rvgj

Опубликовано: 22 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Missing permission check in Jenkins build-publisher Plugin

Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers that the plugin is configured to publish builds to, as well as builds pending for publication to those Jenkins servers. At this time there is no known workaround or fix. The Build-Publisher plugin distribution has been suspended.

Пакеты

Наименование

org.jenkins-ci.plugins:build-publisher

maven
Затронутые версииВерсия исправления

<= 1.22

Отсутствует

EPSS

Процентиль: 60%
0.00396
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862
CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
больше 3 лет назад

Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers that the plugin is configured to publish builds to, as well as builds pending for publication to those Jenkins servers.

EPSS

Процентиль: 60%
0.00396
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862
CWE-863