Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qf42-f5vf-6w99

Опубликовано: 06 сент. 2023
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Disabled permissions granted by Jenkins Assembla Auth Plugin

Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be granted.

Пакеты

Наименование

org.jenkins-ci.plugins:assembla-auth

maven
Затронутые версииВерсия исправления

<= 1.14

Отсутствует

EPSS

Процентиль: 19%
0.00059
Низкий

8.8 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.8
nvd
больше 2 лет назад

Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be granted.

EPSS

Процентиль: 19%
0.00059
Низкий

8.8 High

CVSS3

Дефекты

CWE-862