MEDIUM 6.5 Maven
Missing permission checks in Jenkins Maven Cascade Release Plugin
GHSA-5xv9-gp22-gqm5 · CVE-2020-2294
Published · Modified
Description
Jenkins Maven Cascade Release Plugin 1.3.2 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to start cascade builds and layout builds, and reconfigure the plugin.
Ready to move
Start Securing
Free, no credit card | First findings in minutes