Lucene search

K
osvGoogleOSV:GHSA-XXV9-W5HM-328J
HistoryMar 06, 2024 - 6:30 p.m.

Jenkins AppSpider Plugin missing permission checks

2024-03-0618:30:38
Google
osv.dev
8
jenkins
appspider
plugin
security
permission checks
http endpoints
attackers
scan config
engine group
client names

6.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Jenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about available scan config names, engine group names, and client names.

6.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Related for OSV:GHSA-XXV9-W5HM-328J