Missing Authorization in Jenkins S3 publisher Plugin
Moderate severity
GitHub Reviewed
Published
Jun 16, 2021
to the GitHub Advisory Database
•
Updated Dec 26, 2023
Package
Affected versions
= 0.11.6
< 0.11.5.1
Patched versions
0.11.7
0.11.5.1
Description
Published by the National Vulnerability Database
May 11, 2021
Reviewed
May 19, 2021
Published to the GitHub Advisory Database
Jun 16, 2021
Last updated
Dec 26, 2023
Jenkins S3 publisher Plugin prior to 0.11.7 and 0.11.5.1 does not perform Run/Artifacts permission checks in various HTTP endpoints and API models.
This allows attackers with Item/Read permission to obtain information about artifacts uploaded to S3, if the optional Run/Artifacts permission is enabled.
Jenkins S3 publisher Plugin 0.11.7 and 0.11.5.1 requires Run/Artifacts permission to obtain information about artifacts if this permission is enabled.
References