QID 996807
Date Published: 2024-01-23
QID 996807: Java (Maven) Security Update for com.synopsys.integration:synopsys-detect (GHSA-6w3h-vq7m-v3qf)
Jenkins Black Duck Detect Plugin did not perform permission checks on methods implementing form validation. This allowed users with Overall/Read access to Jenkins to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins, and to cause Jenkins to submit HTTP requests to attacker-specified URLs.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-6w3h-vq7m-v3qf for updates and patch information.
Vendor References
- GHSA-6w3h-vq7m-v3qf -
github.com/advisories/GHSA-6w3h-vq7m-v3qf
CVEs related to QID 996807
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6w3h-vq7m-v3qf | com.synopsys.integration:synopsys-detect |
|