An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users with Overall/Read permission to read and write the Black Duck Hub plugin configuration.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-3630 An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users with Overall/Read permission to read and write the Black Duck Hub plugin configuration.
Github GHSA Github GHSA GHSA-crvq-mw2w-4cfx Jenkins Black Duck Hub Plugin allowed any user with Overall/Read to read and write its configuration
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-17T02:57:51.415Z

Reserved: 2018-06-05T00:00:00Z

Link: CVE-2018-1000197

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-05T21:29:00.713

Modified: 2024-11-21T03:39:54.757

Link: CVE-2018-1000197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses