Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6gp4-2f92-j2w5

Опубликовано: 16 мая 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Jenkins Email Extension Plugin missing permission check

Jenkins Email Extension Plugin 2.96 and earlier does not perform a permission check in a method implementing form validation.

This allows attackers with Overall/Read permission to check for the existence of files in the email-templates/ directory in the Jenkins home directory on the controller file system.

This form validation method requires the appropriate permission in Email Extension Plugin 2.96.1.

Пакеты

Наименование

org.jenkins-ci.plugins:email-ext

maven
Затронутые версииВерсия исправления

< 2.96.1

2.96.1

EPSS

Процентиль: 27%
0.00098
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 4.3
redhat
больше 2 лет назад

Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files in the email-templates/ directory in the Jenkins home directory on the controller file system.

CVSS3: 4.3
nvd
больше 2 лет назад

Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files in the email-templates/ directory in the Jenkins home directory on the controller file system.

EPSS

Процентиль: 27%
0.00098
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-732