[JENKINS:SECURITY-2109-2] Missing permission checks in `chaos-monkey`

Severity Medium
Affected Packages 2
Fixed Packages 2
CVEs 1

chaos-monkey 0.4 and earlier does not perform permission checks in an HTTP endpoint.

This allows attackers with Overall/Read permission to access the Chaos Monkey page and to see the history of actions.

chaos-monkey 0.4.1 requires Overall/Administer permission to access the Chaos Monkey page and to see the history of actions.

ID
JENKINS:SECURITY-2109-2
Severity
medium
Published
2020-12-03T00:00:00
(3 years ago)
Modified
2020-12-03T00:00:00
(3 years ago)
Rights
Jenkins Security Team
Other Advisories
Source # ID Name URL
Plugin repository chaos-monkey repository https://github.com/jenkinsci/chaos-monkey-plugin
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/chaos-monkey org.jenkins-ci.plugins chaos-monkey <= 0.4
Fixed pkg:maven/org.jenkins-ci.plugins/chaos-monkey org.jenkins-ci.plugins chaos-monkey = 0.4.1
Affected pkg:github/jenkinsci/chaos-monkey-plugin jenkinsci chaos-monkey-plugin <= 0.4
Fixed pkg:github/jenkinsci/chaos-monkey-plugin jenkinsci chaos-monkey-plugin = 0.4.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...