QID 983819
QID 983819: Java (maven) Security Update for org.jenkins-ci.plugins:s3 (GHSA-fvfc-8pqr-wjpv)
Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform Run/Artifacts permission checks in various HTTP endpoints and API models, allowing attackers with Item/Read permission to obtain information about artifacts uploaded to S3, if the optional Run/Artifacts permission is enabled.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fvfc-8pqr-wjpv for updates pertaining to this vulnerability.
Vendor References
- GHSA-fvfc-8pqr-wjpv -
github.com/advisories/GHSA-fvfc-8pqr-wjpv
CVEs related to QID 983819
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fvfc-8pqr-wjpv | org.jenkins-ci.plugins:s3 |
|