PT-2018-5172 · Jenkins · Jenkins Multijob Plugin+1

Lars Hupel

·

Publicado

2018-01-26

·

Atualizado

2022-05-13

·

CVE-2017-1000390

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Multijob plugin versions 1.25 and earlier
Description The issue concerns a permission check in the Resume Build action. Specifically, it allows anyone with Job/Read permission to resume the build without proper authorization. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited. Technical details include the lack of permission checks in the Resume Build action, allowing unauthorized access with Job/Read permission.
Recommendations For Jenkins Multijob plugin versions 1.25 and earlier, update to version 1.27 or later to introduce a permission check requiring Job/Build. As a temporary workaround, consider restricting access to the Resume Build action to minimize the risk of exploitation.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-1000390
GHSA-P9R2-GGHQ-HC57

Produtos afetados

Jenkins
Jenkins Multijob Plugin