PT-2013-2241 · Cloudbees+1 · Jenkins
Kurt Seifried
·
Published
2013-03-19
·
Updated
2022-05-05
·
CVE-2013-0330
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Jenkins versions prior to 1.502
Jenkins LTS versions prior to 1.480.3
Description
The issue allows remote authenticated users with write access to build arbitrary jobs. The attack vectors for this issue are not specified.
Recommendations
For versions prior to 1.502, update to version 1.502 or later.
For LTS versions prior to 1.480.3, update to version 1.480.3 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins