Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c4c3-3cgh-vvrh

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Missing permission check in Jenkins requests-plugin Plugin allows viewing pending requests

Jenkins requests-plugin Plugin 2.2.6 and earlier does not perform a permission check in an HTTP endpoint.

This allows attackers with Overall/Read permission to view the list of pending requests.

Jenkins requests-plugin Plugin 2.2.7 requires Overall/Administer permission to view the list of pending requests.

The previous sentence originally stated that Overall/Read permission was newly required. This statement was incorrect and has been fixed on 2021-07-05.

Пакеты

Наименование

org.jenkins-ci.plugins:requests

maven
Затронутые версииВерсия исправления

<= 2.2.6

2.2.7

EPSS

Процентиль: 32%
0.00125
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
больше 4 лет назад

A missing permission check in Jenkins requests-plugin Plugin 2.2.6 and earlier allows attackers with Overall/Read permission to view the list of pending requests.

EPSS

Процентиль: 32%
0.00125
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862