Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-72x3-c7jc-q35x

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Improper authorization in Jenkins Job and Node Ownership Plugin

An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in

OwnershipDescription.java, JobOwnerJobProperty.java, and OwnerNodeProperty.java

that allow an attacker with Job/Configure or Computer/Configure permission and without Ownership related permissions to override ownership metadata.

Пакеты

Наименование

com.synopsys.jenkinsci:ownership

maven
Затронутые версииВерсия исправления

< 0.12.0

0.12.0

EPSS

Процентиль: 5%
0.00021
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 6.5
nvd
почти 8 лет назад

An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in OwnershipDescription.java, JobOwnerJobProperty.java, and OwnerNodeProperty.java that allow an attacker with Job/Configure or Computer/Configure permission and without Ownership related permissions to override ownership metadata.

EPSS

Процентиль: 5%
0.00021
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285