CVE-2020-2294 – com.barchart.jenkins:maven-release-cascade
Package
Manager: maven
Name: com.barchart.jenkins:maven-release-cascade
Vulnerable Version: >=0 <=1.3.2
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00231 pctl0.4581
Details
Missing permission checks in Jenkins Maven Cascade Release Plugin Jenkins Maven Cascade Release Plugin 1.3.2 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to start cascade builds and layout builds, and reconfigure the plugin.
Metadata
Created: 2022-05-24T17:30:19Z
Modified: 2023-10-27T11:56:03Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-5xv9-gp22-gqm5/GHSA-5xv9-gp22-gqm5.json
CWE IDs: ["CWE-862"]
Alternative ID: GHSA-5xv9-gp22-gqm5
Finding: F039
Auto approve: 1