QID 983816
QID 983816: Java (maven) Security Update for org.jenkins-ci.plugins:p4 (GHSA-h6qv-f5gf-8gcf)
Jenkins P4 Plugin 1.11.4 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified Perforce server using attacker-specified username and password.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h6qv-f5gf-8gcf for updates pertaining to this vulnerability.
Vendor References
- GHSA-h6qv-f5gf-8gcf -
github.com/advisories/GHSA-h6qv-f5gf-8gcf
CVEs related to QID 983816
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h6qv-f5gf-8gcf | org.jenkins-ci.plugins:p4 |
|