[MAVEN:GHSA-7V7G-MH53-89HW] Missing permission check in Jenkins AWS Global Configuration Plugin allows replacing plugin configuration

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Jenkins AWS Global Configuration Plugin 1.5 and earlier does not perform a permission check in an HTTP endpoint processing form submissions.

This allows attackers with Overall/Read permission to replace the global AWS configuration.

Jenkins AWS Global Configuration Plugin 1.6 properly performs permission checks when processing configuration form submissions.

ID
MAVEN:GHSA-7V7G-MH53-89HW
Severity
moderate
URL
https://github.com/advisories/GHSA-7v7g-mh53-89hw
Published
2022-05-24T17:33:08
(2 years ago)
Modified
2023-12-14T19:28:44
(9 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.jenkins.plugins/aws-global-configuration io.jenkins.plugins aws-global-configuration <= 1.5
Fixed pkg:maven/io.jenkins.plugins/aws-global-configuration io.jenkins.plugins aws-global-configuration = 1.6
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...