Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2jf-rc5v-vmpv

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Incorrect Authorization in Jenkins

A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.121.2

2.121.3

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.122, <= 2.137

2.138

EPSS

Процентиль: 30%
0.00114
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.

CVSS3: 4.3
redhat
больше 7 лет назад

A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.

CVSS3: 6.5
nvd
больше 7 лет назад

A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.

CVSS3: 6.5
debian
больше 7 лет назад

A improper authorization vulnerability exists in Jenkins 2.137 and ear ...

EPSS

Процентиль: 30%
0.00114
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863