Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9mc6-vgmq-x6xf

Опубликовано: 22 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Lack of authentication mechanism in Jenkins DotCi Plugin webhook

DotCi Plugin provides a webhook endpoint at /githook/ that can be used to trigger builds of the job for a GitHub repository.

In DotCi Plugin 2.40.00 and earlier, this endpoint can be accessed without authentication.

This allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.

This plugin has been suspended.

Пакеты

Наименование

com.groupon.jenkins-ci.plugins:DotCi

maven
Затронутые версииВерсия исправления

<= 2.40.00

Отсутствует

EPSS

Процентиль: 79%
0.01295
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.

EPSS

Процентиль: 79%
0.01295
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-862