[MAVEN:GHSA-73V5-W6FG-2M44] Jenkins Tuleap Git Branch Source Plugin allows unauthenticated attackers to trigger Tuleap projects whose configured repo matches attacker-specified value

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

A missing permission check in Jenkins Tuleap Git Branch Source Plugin 3.2.4 and earlier allows unauthenticated attackers to trigger Tuleap projects whose configured repository matches the attacker-specified value. Tuleap Git Branch Source Plugin 3.2.5 requires a token to access the webhook endpoint.

ID
MAVEN:GHSA-73V5-W6FG-2M44
Severity
moderate
URL
https://github.com/advisories/GHSA-73v5-w6fg-2m44
Published
2022-10-19T19:00:22
(23 months ago)
Modified
2023-02-02T05:08:31
(19 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/tuleap-git-branch-source org.jenkins-ci.plugins tuleap-git-branch-source <= 3.2.4
Fixed pkg:maven/org.jenkins-ci.plugins/tuleap-git-branch-source org.jenkins-ci.plugins tuleap-git-branch-source = 3.2.5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...