Loading HuntDB...

GHSA-xxhf-xq6v-c8mj

GitHub Security Advisory

Improper authorization in Jenkins Embeddable Build Status Plugin bypasses ViewStatus permission requirement

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for \"unprotected\" status badge access.

This allows attackers without any permissions to obtain the build status badge icon for any attacker-specified job and/or build.

Embeddable Build Status Plugin 2.0.4 requires ViewStatus permission to obtain the build status badge icon.

Affected Packages

Maven org.jenkins-ci.plugins:embeddable-build-status
Affected versions: 0 (fixed in 2.0.4)

Related CVEs

Key Information

GHSA ID
GHSA-xxhf-xq6v-c8mj
Published
June 24, 2022 12:00 AM
Last Modified
December 5, 2022 10:35 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:embeddable-build-status
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 25, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.