Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5qh3-hxx9-w26p

Опубликовано: 24 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.

Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.

EPSS

Процентиль: 35%
0.00428
Низкий

8.8 High

CVSS3

Дефекты

CWE-610

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 месяцев назад

Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.

EPSS

Процентиль: 35%
0.00428
Низкий

8.8 High

CVSS3

Дефекты

CWE-610