Authentication mechanism absence or evasion In org.jenkins-ci.plugins:mercurial
Description
Incorrect Authorization in Jenkins Mercurial Plugin An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker with network access to obtain a list of nodes and users.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 2.3 |
Aliases
1. 2. 3. 4.
References
1. 2.