Improper authorization control for web services In github.com/go-gitea/gitea
Description
Improper handling of untrusted branches in Gitea Jenkins Plugin Jenkins Gitea Plugin prior to 1.1.2 did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | v1.1.2 | ||
maven | 1.1.2 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4.