Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5q7j-8hpc-4848

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Server-side request forgery vulnerability in Jenkins Mesos Plugin

An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Пакеты

Наименование

org.jenkins-ci.plugins:mesos

maven
Затронутые версииВерсия исправления

<= 0.17.1

0.18

EPSS

Процентиль: 55%
0.00326
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.5
nvd
около 7 лет назад

An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

EPSS

Процентиль: 55%
0.00326
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-918