Описание
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds possibly failing to download a JDK.
Ссылки
- Third Party AdvisoryVDB Entry
- Issue Tracking
- Patch
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Issue Tracking
- Patch
- Vendor Advisory
Уязвимые конфигурации
EPSS
5.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
Связанные уязвимости
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds possibly failing to download a JDK.
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds possibly failing to download a JDK.
In Jenkins before versions 2.44, 2.32.2 low privilege users were able ...
Incorrect Permission Assignment for Critical Resource in Jenkins
EPSS
5.4 Medium
CVSS3
5.5 Medium
CVSS2