Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g28p-6mcc-v4rv

Опубликовано: 10 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".

Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".

EPSS

Процентиль: 14%
0.00234
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
redhat
около 2 месяцев назад

Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".

CVSS3: 4.3
nvd
около 2 месяцев назад

Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".

EPSS

Процентиль: 14%
0.00234
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862