Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mm9c-4cv4-7rfv

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

Jenkins allows for Privilege Escalation by Remote Authenticated Users

The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 1.597, < 1.600

1.600

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 1.596.1

1.596.1

EPSS

Процентиль: 70%
0.00639
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-266

Связанные уязвимости

ubuntu
больше 10 лет назад

The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.

redhat
почти 11 лет назад

The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.

nvd
больше 10 лет назад

The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.

debian
больше 10 лет назад

The combination filter Groovy script in Jenkins before 1.600 and LTS b ...

EPSS

Процентиль: 70%
0.00639
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-266