Lucene search

K
osvGoogleOSV:GHSA-Q6RQ-4WHR-R879
HistoryMay 24, 2022 - 5:33 p.m.

Missing permission check in Jenkins Active Directory Plugin allows accessing domain health check page

2022-05-2417:33:07
Google
osv.dev
7

4.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.2%

Jenkins Active Directory Plugin 2.19 and earlier does not perform a permission check in an HTTP endpoint.

This allows attackers with Overall/Read permission to access the domain health check diagnostic page.

Jenkins Active Directory Plugin 2.20 requires Overall/Administer permission to access the domain health check diagnostic page.

4.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.2%

Related for OSV:GHSA-Q6RQ-4WHR-R879