Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mc22-25r3-2w9w

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Parameterized Trigger Plugin fails to check Item/Build permission

Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins. The plugin has been adapted to now check for Item/Build permission before triggering a downstream build.

Пакеты

Наименование

org.jenkins-ci.plugins:parameterized-trigger

maven
Затронутые версииВерсия исправления

< 2.35.1

2.35.1

EPSS

Процентиль: 11%
0.00038
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 6.5
nvd
больше 8 лет назад

Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.

EPSS

Процентиль: 11%
0.00038
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-276