PT-2020-15516 · Jenkins · Jenkins Role-Based Authorization Strategy Plugin+1
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins Role-based Authorization Strategy Plugin versions 3.0 and earlier
Description
The issue arises from the improper invalidation of a permission cache when the configuration is changed, resulting in permissions being granted based on an outdated configuration. This can lead to permissions being granted long after the configuration was changed to no longer grant them.
Recommendations
For Jenkins Role-based Authorization Strategy Plugin versions 3.0 and earlier, update to version 3.1 or newer to properly invalidate the cache on configuration changes.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Role-Based Authorization Strategy Plugin