[MAVEN:GHSA-5Q7J-8HPC-4848] Server-side request forgery vulnerability in Jenkins Mesos Plugin

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/mesos <= 0.17.1
Package Fixed Version
pkg:maven/org.jenkins-ci.plugins/mesos = 0.18
ID
MAVEN:GHSA-5Q7J-8HPC-4848
Severity
moderate
URL
https://github.com/advisories/GHSA-5q7j-8hpc-4848
Published
2022-05-14T01:38:17
(2 years ago)
Modified
2024-01-30T22:11:18
(7 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/mesos org.jenkins-ci.plugins mesos <= 0.17.1
Fixed pkg:maven/org.jenkins-ci.plugins/mesos org.jenkins-ci.plugins mesos = 0.18
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...