Vulnerability GHSA-jv82-75fh-23r7

Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 year ago
November 13, 2024 at 09:30 PM UTC
Missing permission check in Jenkins Script Security Plugin
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1

Summary

Missing permission check in Jenkins Script Security Plugin

Details

Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system. This allows attackers with Overall/Read permission to check for the existence of files on the controller file system. Script Security Plugin 1368.vb_b_402e3547e7 requires Overall/Administer permission for the affected form validation method.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

High Risk
3 months ago
Jenkins Script Security Plugin sandbox bypass vulnerability
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-c3jm-9vj7-5v66
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-c3jm-9vj7-5v66
High Risk
3 months ago
Jenkins Script Security Plugin has a script security bypass vulnerability
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-cfj9-2vgr-hpxp
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-cfj9-2vgr-hpxp
Medium Risk
5 months ago
Jenkins Script Security Plugin: Missing permission checks allow enumeration of pending and approved classpaths
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-p334-gfhq-c7w6
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-p334-gfhq-c7w6
High Risk
2 years ago
Jenkins Script Security Plugin sandbox bypass vulnerability
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-2g4q-9vm9-9fw4
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-2g4q-9vm9-9fw4
High Risk
2 years ago
Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodies
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-v63g-v339-2673
1.0.0 - 1.31.0 and 1.33.0 - 1.53.0 and 1.55.0 - 1.56.0 and 1.58.0 - 1.65.0 and 1.67.0 - 1.78.1 GHSA-v63g-v339-2673
View all vulnerabilities for these packages

Timeline

Published
1 year ago
November 13, 2024 at 09:30 PM UTC
Last Modified
1 month ago
August 07, 2026 at 08:12 AM UTC