Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7j3x-xm4j-jfj7

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Missing permission checks in Jenkins Warnings Next Generation Plugin allow listing workspace contents

Jenkins Warnings Next Generation Plugin 8.4.4 and earlier does not perform permission checks in methods implementing form validation.

This allows attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file patterns match workspace contents. A sequence of requests can be used to effectively list workspace contents.

Jenkins Warnings Next Generation Plugin 8.5.0 requires Item/Configure permission to validate patterns with workspace contents.

Пакеты

Наименование

io.jenkins.plugins:warnings-ng

maven
Затронутые версииВерсия исправления

<= 8.4.4

8.5.0

EPSS

Процентиль: 8%
0.00031
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
почти 5 лет назад

Jenkins Warnings Next Generation Plugin 8.4.4 and earlier does not perform a permission check in methods implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file patterns match workspace contents.

EPSS

Процентиль: 8%
0.00031
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862