[MAVEN:GHSA-VP68-FM96-7V79] Jenkins Android Signing Plugin allows attackers to check whether attacker-specified file patterns match workspace contents

Severity Moderate
Affected Packages 1
CVEs 1

Jenkins Android Signing Plugin 2.2.5 and earlier does not perform a permission check in a method implementing form validation.

This allows attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file patterns match workspace contents. A sequence of requests can be used to effectively list workspace contents.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/android-signing <= 2.2.5
ID
MAVEN:GHSA-VP68-FM96-7V79
Severity
moderate
URL
https://github.com/advisories/GHSA-vp68-fm96-7v79
Published
2022-07-28T00:00:42
(2 years ago)
Modified
2024-01-03T13:31:24
(8 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/android-signing org.jenkins-ci.plugins android-signing <= 2.2.5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...