Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9r7f-rqhw-j8h8

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.8

Описание

Incorrect permission checks in Pipeline: Nodes and Processes plugin

On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline node blocks on those agents due to incorrect permissions checks in Pipeline: Nodes and Processes plugin 2.17 and earlier.

Пакеты

Наименование

org.jenkins-ci.plugins.workflow:workflow-durable-task-step

maven
Затронутые версииВерсия исправления

<= 2.17

2.18

EPSS

Процентиль: 9%
0.00033
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.2
redhat
около 8 лет назад

On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline `node` blocks on those agents due to incorrect permissions checks in Pipeline: Nodes and Processes plugin 2.17 and earlier.

CVSS3: 4.8
nvd
около 8 лет назад

On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline `node` blocks on those agents due to incorrect permissions checks in Pipeline: Nodes and Processes plugin 2.17 and earlier.

EPSS

Процентиль: 9%
0.00033
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-862