Description
On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline `node` blocks on those agents due to incorrect permissions checks in Pipeline: Nodes and Processes plugin 2.17 and earlier.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3440 | On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline `node` blocks on those agents due to incorrect permissions checks in Pipeline: Nodes and Processes plugin 2.17 and earlier. |
Github GHSA |
GHSA-9r7f-rqhw-j8h8 | Incorrect permission checks in Pipeline: Nodes and Processes plugin |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T03:03:42.519Z
Reserved: 2018-01-23T00:00:00.000Z
Link: CVE-2018-1000015
No data.
Status : Modified
Published: 2018-01-23T14:29:00.720
Modified: 2024-11-21T03:39:25.980
Link: CVE-2018-1000015
OpenCVE Enrichment
No data.
EUVD
Github GHSA