Missing permission checks in Jenkins ElectricFlow Plugin 1.1.5 and earlier in various HTTP endpoints allowed users with Overall/Read access to obtain information about the Jenkins ElectricFlow Plugin configuration and configuration of connected ElectricFlow instances.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2019/06/11/1 | third party advisory mailing list |
http://www.securityfocus.com/bid/108747 | vdb entry third party advisory |
https://jenkins.io/security/advisory/2019-06-11/#SECURITY-1410%20%282%29 |