Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-55657
HistoryJun 24, 2022 - 12:00 a.m.

Jenkins ThreadFix Plugin Licensing Issue Vulnerability

2022-06-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
12

0.001 Low

EPSS

Percentile

22.0%

Jenkins and Jenkins Plugin are both Jenkins open source products.Jenkins is an application. An open source automation server, Jenkins provides hundreds of plugins to support building, deploying, and automating any project.Jenkins Plugin is an application.An authorization issue vulnerability exists in Jenkins ThreadFix Plugin version 1.5.4 and earlier, which stems from the plugin’s failure to perform permission check. An attacker with overall/read permissions could use this vulnerability to connect to the URL specified by the attacker.

CPENameOperatorVersion
jenkins threadfix pluginlt1.5.4

0.001 Low

EPSS

Percentile

22.0%

Related for CNVD-2022-55657