QID 997974
Date Published: 2024-04-08
QID 997974: Java (Maven) Security Update for org.jenkins-ci.main:jenkins-core (GHSA-7fpg-pp3m-h22f)
BuildTrigger in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to bypass access restrictions and execute arbitrary jobs by configuring a job to trigger another job. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7330.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-7fpg-pp3m-h22f for updates and patch information.
Vendor References
- GHSA-7fpg-pp3m-h22f -
github.com/advisories/GHSA-7fpg-pp3m-h22f
CVEs related to QID 997974
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7fpg-pp3m-h22f | org.jenkins-ci.main:jenkins-core |
|