GHSA-rqqx-fvqx-539g
GitHub Security Advisory
Jenkins Deployer Framework Plugin allows attackers with Item/Read permission to read deployment logs
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not perform a permission check in an HTTP endpoint.
This allows attackers with Item/Read permission to read deployment logs.
Deployer Framework Plugin 86.v7b_a_4a_55b_f3ec requires Deploy Now/Deploy permission to read deployment logs.
Affected Packages
Maven
org.jenkins-ci.plugins:deployer-framework
Affected versions:
0
(fixed in 86.v7b_a_4a_55b_f3ec)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 5, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.