Описание
CSRF vulnerability and missing permission checks in Jenkins AbsInt Astrée Plugin
A command execution vulnerability exists in Jenkins Absint Astree Plugin 1.0.5 and older in AstreeBuilder.java that allows attackers with Overall/Read access to execute a command on the Jenkins master.
Пакеты
Наименование
org.jenkins-ci.plugins:absint-astree
maven
Затронутые версииВерсия исправления
<= 1.0.5
1.0.7
Связанные уязвимости
CVSS3: 8.8
nvd
больше 7 лет назад
A command execution vulnerability exists in Jenkins Absint Astree Plugin 1.0.5 and older in AstreeBuilder.java that allows attackers with Overall/Read access to execute a command on the Jenkins master.