Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9rx5-w522-5fh7

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Jenkins Promoted Builds Plugin allowed unauthorized users to run some promotion processes

An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.

Пакеты

Наименование

org.jenkins-ci.plugins:promoted-builds

maven
Затронутые версииВерсия исправления

<= 2.31.1

3.0

EPSS

Процентиль: 8%
0.00031
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
redhat
почти 8 лет назад

An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.

CVSS3: 4.3
nvd
почти 8 лет назад

An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.

EPSS

Процентиль: 8%
0.00031
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863