QID 996119
Date Published: 2023-11-30
QID 996119: Java (Maven) Security Update for org.jenkins-ci.plugins:google-compute-engine (GHSA-pgpj-83g3-mfr2)
Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier does not correctly perform permission checks in multiple HTTP endpoints. This allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to do the following:
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-pgpj-83g3-mfr2 for updates and patch information.
Vendor References
- GHSA-pgpj-83g3-mfr2 -
github.com/advisories/GHSA-pgpj-83g3-mfr2
CVEs related to QID 996119
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pgpj-83g3-mfr2 | org.jenkins-ci.plugins:google-compute-engine |
|