GHSA-c445-xm3f-hmfh
GitHub Security Advisory
Incorrect permission check in Health Advisor by CloudBees Plugin
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP endpoint.
This allows attackers with Overall/Read permission to view an administrative configuration page.
Health Advisor by CloudBees Plugin 3.2.1 requires Overall/Administer to view its administrative configuration page.
Affected Packages
Maven
org.jenkins-ci.plugins:cloudbees-jenkins-advisor
Affected versions:
0
(fixed in 3.2.1)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 3, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.