Описание
Jenkins Failed Job Deactivator Plugin Missing Authorization vulnerability
Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier does not perform permission checks in several views and HTTP endpoints.
This allows attackers with Overall/Read permission to disable jobs.
Additionally, these endpoints do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.
As of publication of this advisory, there is no fix.
Пакеты
Наименование
de.einsundeins.jenkins.plugins.failedjobdeactivator:failedJobDeactivator
maven
Затронутые версииВерсия исправления
<= 1.2.1
Отсутствует
Связанные уязвимости
CVSS3: 4.3
nvd
больше 3 лет назад
Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier does not perform permission checks in several views and HTTP endpoints, allowing attackers with Overall/Read permission to disable jobs.