Improper authorization control for web services In org.jenkins-ci.plugins:github-branch-source

Description

Jenkins GitHub Branch Source Plugin: Missing permissions check allows attackers to perform a connection test Jenkins GitHub Branch Source Plugin versions 1967.vdea_d580c1a_b_a_ and earlier do not perform a permission check in a method implementing form validation.

This allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.

GitHub Branch Source Plugin 1967.1969.v205fd594c821 requires Overall/Manage permission to perform the connection test.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions