Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system.
Metrics
Affected Vendors & Products
References
History
Wed, 13 Nov 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-862 | |
Metrics |
cvssV3_1
|
Wed, 13 Nov 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: jenkins
Published: 2024-11-13T20:53:00.291Z
Updated: 2024-11-13T21:35:30.700Z
Reserved: 2024-11-12T15:28:28.980Z
Link: CVE-2024-52549
Vulnrichment
Updated: 2024-11-13T21:35:23.410Z
NVD
Status : Received
Published: 2024-11-13T21:15:29.233
Modified: 2024-11-13T22:35:09.080
Link: CVE-2024-52549
Redhat
No data.