Loading HuntDB...

GHSA-2482-gr3v-f3f3

GitHub Security Advisory

Jenkins Fogbugz Plugin has missing permissions check

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins Fogbugz Plugin provides a webhook endpoint at `/fbTrigger/` that can be used to trigger builds of any jobs.

In Fogbugz Plugin 2.2.17 and earlier, this endpoint can be accessed by attackers with Item/Read permission, allowing them to trigger builds of jobs specified in a `jobname` request parameter.

Affected Packages

Maven org.jenkins-ci.plugins:fogbugz
Affected versions: 0 (last affected: 2.2.17)

Related CVEs

Key Information

GHSA ID
GHSA-2482-gr3v-f3f3
Published
April 12, 2023 6:30 PM
Last Modified
April 12, 2023 10:18 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:fogbugz
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 25, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.