Lucene search

K
osvGoogleOSV:GHSA-8JX9-7J5M-79X4
HistoryMay 13, 2022 - 1:40 a.m.

Jenkins Build Step Plugin fails to check Item/Build permission

2022-05-1301:40:54
Google
osv.dev
3

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.5%

Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.5%

Related for OSV:GHSA-8JX9-7J5M-79X4