QID 997337
Date Published: 2024-02-20
QID 997337: Java (Maven) Security Update for org.jenkins-ci.plugins:absint-astree (GHSA-c9px-7j36-f35v)
A command execution vulnerability exists in Jenkins Absint Astree Plugin 1.0.5 and older in AstreeBuilder.java that allows attackers with Overall/Read access to execute a command on the Jenkins master.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-c9px-7j36-f35v for updates and patch information.
Vendor References
- GHSA-c9px-7j36-f35v -
github.com/advisories/GHSA-c9px-7j36-f35v
CVEs related to QID 997337
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c9px-7j36-f35v | org.jenkins-ci.plugins:absint-astree |
|