Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45844
HistoryMar 12, 2024 - 7:40 a.m.

Improper Authorization

2024-03-1207:40:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4
improper authorization
jenkins
docker build

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

org.jenkins-ci.plugins:docker-build-step is vulnerable to Improper Authorization. The vulnerability is due to inadequate permission validation, allowing attackers with Overall/Read permission to connect to attacker-specified TCP or Unix socket URLs and reconfigure the plugin using provided connection test parameters, affecting future build step executions.

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%