Lucene search

K
githubGitHub Advisory DatabaseGHSA-8H2M-54WH-GWJ3
HistoryMar 06, 2024 - 6:30 p.m.

Jenkins docker-build-step Plugin missing permission check

2024-03-0618:30:39
GitHub Advisory Database
github.com
5
jenkins
docker-build-step plugin
missing permission check
http endpoint
overall/read permission
tcp
unix socket url
reconfigure
connection test parameters
build step executions
software

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions.

Affected configurations

Vulners
Node
jenkinspipeline\Match_build_stepjenkins

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

Related for GHSA-8H2M-54WH-GWJ3