Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8hh2-rxm8-7fj8

Опубликовано: 30 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Missing permission check in Jenkins Continuous Integration with Toad Edge Plugin

A missing permission check in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

Пакеты

Наименование

org.jenkins-ci.plugins:ci-with-toad-edge

maven
Затронутые версииВерсия исправления

< 2.4

2.4

EPSS

Процентиль: 65%
0.00497
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-281
CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
почти 4 года назад

A missing permission check in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

EPSS

Процентиль: 65%
0.00497
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-281
CWE-862