Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/101946 | vdb entry |
https://jenkins.io/security/advisory/2017-06-06/ | vendor advisory |