[MAVEN:GHSA-4XMF-344Q-M4CC] Jenkins Fortify Plugin missing permission check

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Jenkins Fortify Plugin 22.1.38 and earlier does not perform permission checks in several HTTP endpoints.

This allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Additionally, these HTTP endpoints do not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.

Fortify Plugin 22.2.39 requires POST requests and the appropriate permissions for the affected HTTP endpoints.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/fortify <= 22.1.38
Package Fixed Version
pkg:maven/org.jenkins-ci.plugins/fortify = 22.2.39
ID
MAVEN:GHSA-4XMF-344Q-M4CC
Severity
moderate
URL
https://github.com/advisories/GHSA-4xmf-344q-m4cc
Published
2023-08-22T00:31:10
(13 months ago)
Modified
2023-11-09T05:03:30
(10 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/fortify org.jenkins-ci.plugins fortify <= 22.1.38
Fixed pkg:maven/org.jenkins-ci.plugins/fortify org.jenkins-ci.plugins fortify = 22.2.39
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...