GHSA-8h2m-54wh-gwj3
GitHub Security Advisory
Jenkins docker-build-step Plugin missing permission check
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions.
Affected Packages
Maven
org.jenkins-ci.plugins:docker-build-step
Affected versions:
0
(last affected: 2.11)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 6, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.