Improper authorization control for web services In org.jenkins-ci.plugins:mercurial
Description
Missing Authorization in Jenkins Mercurial Plugin Mercurial Plugin prior to 2.12, 2.10.1, 2.9.1, and 2.8.1 does not perform a permission check in an HTTP endpoint.
This allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.
Mercurial Plugin 2.12, 2.10.1, 2.9.1, and 2.8.1 performs permission checks when listing configured Mercurial installations.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 2.12, 2.10.1, 2.9.1, 2.8.1 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.