logo

CVE-2020-2294 com.barchart.jenkins:maven-release-cascade

Package

Manager: maven
Name: com.barchart.jenkins:maven-release-cascade
Vulnerable Version: >=0 <=1.3.2

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00231 pctl0.4581

Details

Missing permission checks in Jenkins Maven Cascade Release Plugin Jenkins Maven Cascade Release Plugin 1.3.2 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to start cascade builds and layout builds, and reconfigure the plugin.

Metadata

Created: 2022-05-24T17:30:19Z
Modified: 2023-10-27T11:56:03Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5xv9-gp22-gqm5/GHSA-5xv9-gp22-gqm5.json
CWE IDs: ["CWE-862"]
Alternative ID: GHSA-5xv9-gp22-gqm5
Finding: F039
Auto approve: 1