Loading HuntDB...

GHSA-jv82-75fh-23r7

GitHub Security Advisory

Missing permission check in Jenkins Script Security Plugin

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system. This allows attackers with Overall/Read permission to check for the existence of files on the controller file system. Script Security Plugin 1368.vb_b_402e3547e7 requires Overall/Administer permission for the affected form validation method.

Affected Packages

Maven org.jenkins-ci.plugins:script-security
Affected versions: 0 (fixed in 1368.vb)

Related CVEs

Key Information

GHSA ID
GHSA-jv82-75fh-23r7
Published
November 13, 2024 9:30 PM
Last Modified
November 14, 2024 3:35 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:script-security
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 1, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.