QID 996968
Date Published: 2024-01-31
QID 996968: Java (Maven) Security Update for org.jenkins-ci.plugins:assembla-auth (GHSA-qf42-f5vf-6w99)
Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be granted.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qf42-f5vf-6w99 for updates and patch information.
Vendor References
- GHSA-qf42-f5vf-6w99 -
github.com/advisories/GHSA-qf42-f5vf-6w99
CVEs related to QID 996968
Software Advisories
| Advisory ID | Software | Component | Link |
|---|