Improper handling of untrusted branches in Gitea Jenkins Plugin
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Dec 5, 2023
Description
Published by the National Vulnerability Database
May 31, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Sep 15, 2022
Last updated
Dec 5, 2023
Jenkins Gitea Plugin prior to 1.1.2 did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted.
References