Incorrect Permission Assignment for Critical Resource in Jenkins Credentials Binding Plugin
Moderate severity
GitHub Reviewed
Published
Jan 13, 2022
to the GitHub Advisory Database
•
Updated Jul 3, 2024
Package
Affected versions
>= 1.25, < 1.27.1
< 1.24.1
Patched versions
1.27.1
1.24.1
Description
Published by the National Vulnerability Database
Jan 12, 2022
Published to the GitHub Advisory Database
Jan 13, 2022
Reviewed
Jun 20, 2022
Last updated
Jul 3, 2024
Jenkins Credentials Binding Plugin prior to 1.27.1 and 1.24.1 does not perform a permission check in a method implementing form validation.
This allows attackers with Overall/Read access to validate if a credential ID refers to a secret file credential and whether it’s a zip file.
Credentials Binding Plugin 1.27.1 and 1.24.1 performs permission checks when validating secret file credentials IDs.
References