Description
Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission to access the Chaos Monkey page and to see the history of actions.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4234 | Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission to access the Chaos Monkey page and to see the history of actions. |
Github GHSA |
GHSA-hx53-635r-vmv8 | Missing permission checks in Jenkins Chaos Monkey Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-04T07:09:54.327Z
Reserved: 2019-12-05T00:00:00.000Z
Link: CVE-2020-2323
No data.
Status : Modified
Published: 2020-12-03T16:15:12.917
Modified: 2024-11-21T05:25:19.110
Link: CVE-2020-2323
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA