Description
A data modification vulnerability exists in Jenkins Agiletestware Pangolin Connector for TestRail Plugin 2.1 and earlier in GlobalConfig.java that allows attackers with Overall/Read permission to override this plugin's configuration by sending crafted HTTP requests to an unprotected endpoint.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4843 | A data modification vulnerability exists in Jenkins Agiletestware Pangolin Connector for TestRail Plugin 2.1 and earlier in GlobalConfig.java that allows attackers with Overall/Read permission to override this plugin's configuration by sending crafted HTTP requests to an unprotected endpoint. |
Github GHSA |
GHSA-pwrm-8mvm-p2f2 | Jenkins Agiletestware Pangolin Connector for TestRail Plugin CSRF vulnerability and missing permission checks |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T20:41:57.324Z
Reserved: 2018-08-01T00:00:00.000Z
Link: CVE-2018-1999032
No data.
Status : Modified
Published: 2018-08-01T13:29:00.687
Modified: 2024-11-21T03:57:05.900
Link: CVE-2018-1999032
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA