Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q4wp-8c99-69pw

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Improper permission checks allow canceling queue items and aborting builds in Jenkins

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.

Jenkins 2.300, LTS 2.289.2 requires that users have Item/Read permission for applicable types in addition to Item/Cancel permission.

As a workaround on earlier versions of Jenkins, do not grant Item/Cancel permission to users who do not have Item/Read permission.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.289.1

2.289.2

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.292, <= 2.299

2.300

EPSS

Процентиль: 78%
0.01173
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
redhat
больше 4 лет назад

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.

CVSS3: 4.3
nvd
больше 4 лет назад

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.

CVSS3: 4.3
debian
больше 4 лет назад

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to can ...

EPSS

Процентиль: 78%
0.01173
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863