[MAVEN:GHSA-25F2-WGXJ-PH29] Missing permission check in Jenkins Job and Node ownership Plugin

Severity Moderate
Affected Packages 1
CVEs 1

A missing permission check in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers with Item/Read permission to change the owners and item-specific permissions of a job.

Package Affected Version
pkg:maven/com.synopsys.jenkinsci/ownership <= 0.13.0
ID
MAVEN:GHSA-25F2-WGXJ-PH29
Severity
moderate
URL
https://github.com/advisories/GHSA-25f2-wgxj-ph29
Published
2022-03-30T00:00:23
(2 years ago)
Modified
2023-02-02T05:05:35
(19 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.synopsys.jenkinsci/ownership com.synopsys.jenkinsci ownership <= 0.13.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...