Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4gh2-m88h-8cj8

Опубликовано: 06 сент. 2023
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Disabled permissions can be granted by Jenkins SSH2 Easy Plugin

Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.

Пакеты

Наименование

org.jenkins-ci.plugins:ssh2easy

maven
Затронутые версииВерсия исправления

< 1.6

1.6

EPSS

Процентиль: 19%
0.00059
Низкий

8.8 High

CVSS3

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 8.8
nvd
больше 2 лет назад

Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.

EPSS

Процентиль: 19%
0.00059
Низкий

8.8 High

CVSS3

Дефекты

CWE-281