[MAVEN:GHSA-XR8H-WJ4V-RX7F] Missing permission check in Jenkins TestQuality Updater Plugin

Severity Moderate
Affected Packages 1
CVEs 1

A missing check in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.

ID
MAVEN:GHSA-XR8H-WJ4V-RX7F
Severity
moderate
URL
https://github.com/advisories/GHSA-xr8h-wj4v-rx7f
Published
2023-01-26T21:30:18
(20 months ago)
Modified
2023-02-03T20:35:21
(19 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/testquality-updater org.jenkins-ci.plugins testquality-updater <= 1.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...