Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fvfc-8pqr-wjpv

Опубликовано: 16 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Missing Authorization in Jenkins S3 publisher Plugin

Jenkins S3 publisher Plugin prior to 0.11.7 and 0.11.5.1 does not perform Run/Artifacts permission checks in various HTTP endpoints and API models.

This allows attackers with Item/Read permission to obtain information about artifacts uploaded to S3, if the optional Run/Artifacts permission is enabled.

Jenkins S3 publisher Plugin 0.11.7 and 0.11.5.1 requires Run/Artifacts permission to obtain information about artifacts if this permission is enabled.

Пакеты

Наименование

org.jenkins-ci.plugins:s3

maven
Затронутые версииВерсия исправления

= 0.11.6

0.11.7

Наименование

org.jenkins-ci.plugins:s3

maven
Затронутые версииВерсия исправления

< 0.11.5.1

0.11.5.1

EPSS

Процентиль: 15%
0.00048
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
больше 4 лет назад

Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform Run/Artifacts permission checks in various HTTP endpoints and API models, allowing attackers with Item/Read permission to obtain information about artifacts uploaded to S3, if the optional Run/Artifacts permission is enabled.

EPSS

Процентиль: 15%
0.00048
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862