Lucene search

K
osvGoogleOSV:GHSA-XV69-6RF3-W5G2
HistoryMay 24, 2022 - 5:45 p.m.

Missing permission check in Jenkins Cloud Statistics Plugin

2022-05-2417:45:45
Google
osv.dev
8

4.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.0%

Jenkins Cloud Statistics Plugin 0.26 and earlier does not perform a permission check in an HTTP endpoint.

This allows attackers with Overall/Read permission and knowledge of random activity IDs to view related provisioning exception error messages.

Jenkins Cloud Statistics Plugin 0.27 requires Overall/Administer permission to access provisioning exception error messages.

4.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.0%

Related for OSV:GHSA-XV69-6RF3-W5G2