[MAVEN:GHSA-2MGJ-MWVF-MPG5] Missing permission checks in Jenkins Proxmox Plugin

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Jenkins Proxmox Plugin 0.7.0 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified host using attacker-specified username and password (perform a connection test), disable SSL/TLS validation for the entire Jenkins controller JVM as part of the connection test (see CVE-2022-28142), and test a rollback with attacker-specified parameters.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/proxmox <= 0.7.0
Package Fixed Version
pkg:maven/org.jenkins-ci.plugins/proxmox = 0.7.1
ID
MAVEN:GHSA-2MGJ-MWVF-MPG5
Severity
moderate
URL
https://github.com/advisories/GHSA-2mgj-mwvf-mpg5
Published
2022-03-30T00:00:24
(2 years ago)
Modified
2024-01-30T22:05:13
(7 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/proxmox org.jenkins-ci.plugins proxmox <= 0.7.0
Fixed pkg:maven/org.jenkins-ci.plugins/proxmox org.jenkins-ci.plugins proxmox = 0.7.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...