Improper authorization control for web services In org.jenkins-ci.plugins:lucene-search
Description
Lucene-Search Plugin does not perform permission checks in several HTTP endpoints Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform permission checks in several HTTP endpoints.
This allows attackers with Overall/Read permission to reindex the database and to obtain information about jobs otherwise inaccessible to them.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 387.v938a |
Aliases
1. 2. 3. 4.
References
1. 2. 3.