The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2013-11-25 19:55
Updated : 2024-02-04 18:16
NVD link : CVE-2013-6373
Mitre link : CVE-2013-6373
CVE.ORG link : CVE-2013-6373
JSON object : View
Products Affected
jenkins-ci
- exclusion
CWE
CWE-264
Permissions, Privileges, and Access Controls