QID 997322
Date Published: 2024-02-20
QID 997322: Java (Maven) Security Update for org.jenkins-ci.plugins.workflow:workflow-durable-task-step (GHSA-9r7f-rqhw-j8h8)
On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline node blocks on those agents due to incorrect permissions checks in Pipeline: Nodes and Processes plugin 2.17 and earlier.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9r7f-rqhw-j8h8 for updates and patch information.
Vendor References
- GHSA-9r7f-rqhw-j8h8 -
github.com/advisories/GHSA-9r7f-rqhw-j8h8
CVEs related to QID 997322
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9r7f-rqhw-j8h8 | org.jenkins-ci.plugins.workflow:workflow-durable-task-step |
|