Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w2j3-pq63-339w

Опубликовано: 16 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Incorrect permission checks in Jenkins Support Core Plugin

Support Core Plugin defines the permission Support/DownloadBundle that allows users without Overall/Administer permission to create and download support bundles containing a limited set of diagnostic information.

Support Core Plugin 1206.v14049fa_b_d860 and earlier does not correctly perform permission checks in several HTTP endpoints.

This allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users with Overall/Administer permission.

Support Core Plugin 1206.1208.v9b_7a_1d48db_0f deprecates the Support/DownloadBundle permission. The Overall/Administer permission is now required to download support bundles.

Пакеты

Наименование

org.jenkins-ci.plugins:support-core

maven
Затронутые версииВерсия исправления

<= 1206.v14049fa

1206.1208.v9b_7a_1d48db_0f

EPSS

Процентиль: 73%
0.00752
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-276
CWE-863

Связанные уязвимости

CVSS3: 6.5
nvd
около 3 лет назад

An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users with Overall/Administer permission.

EPSS

Процентиль: 73%
0.00752
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-276
CWE-863