GHSA-xxhf-xq6v-c8mj
GitHub Security Advisory
Improper authorization in Jenkins Embeddable Build Status Plugin bypasses ViewStatus permission requirement
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for \"unprotected\" status badge access.
This allows attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.
Embeddable Build Status Plugin 2.0.4 requires ViewStatus permission to obtain the build status badge icon.
Affected Packages
Maven
org.jenkins-ci.plugins:embeddable-build-status
Affected versions:
0
(fixed in 2.0.4)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.