Описание
Missing permission check in Jenkins Avatar Plugin
A missing permission check in Jenkins Avatar Plugin 1.2 and earlier allows attackers with Overall/Read access to change the avatar of any user of Jenkins.
Пакеты
Наименование
net.hurstfrost.jenkins:avatar
maven
Затронутые версииВерсия исправления
Отсутствует
Связанные уязвимости
CVSS3: 4.3
nvd
больше 6 лет назад
A missing permission check in Jenkins Avatar Plugin 1.2 and earlier allows attackers with Overall/Read access to change the avatar of any user of Jenkins.