[MAVEN:GHSA-MR38-G7Q2-X79P] Jenkins Openstack Heat Plugin does not perform permission checks in methods implementing form validation

Severity Moderate
Affected Packages 1
CVEs 1

Jenkins openstack-heat Plugin 1.5 and earlier does not perform permission checks in methods implementing form validation.

This allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system. A sequence of requests can be used to effectively list the Jenkins controller file system.

As of publication of this advisory, there is no fix.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/openstack-heat <= 1.5
ID
MAVEN:GHSA-MR38-G7Q2-X79P
Severity
moderate
URL
https://github.com/advisories/GHSA-mr38-g7q2-x79p
Published
2022-07-28T00:00:42
(2 years ago)
Modified
2023-10-27T20:49:26
(10 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/openstack-heat org.jenkins-ci.plugins openstack-heat <= 1.5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...