Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-28155
HistoryMar 06, 2024 - 5:15 p.m.

Design/Logic Flaw

2024-03-0617:15:00
PRIOn knowledge base
www.prio-n.com
9
design flaw
logic flaw
jenkins appspider plugin
permission checks
http endpoints
information disclosure

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%

Jenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about available scan config names, engine group names, and client names.

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%

Related for PRION:CVE-2024-28155