GHSA-49f2-j3pp-22jm

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-49f2-j3pp-22jm/GHSA-49f2-j3pp-22jm.json
Aliases
  • CVE-2023-33003
Published
2023-05-16T18:30:16Z
Modified
2023-05-25T21:45:56.799906Z
Details

Jenkins Tag Profiler Plugin 0.2 and earlier does not perform a permission check in an HTTP endpoint.

This allows attackers with Overall/Read permission to reset profiler statistics.

Additionally, this HTTP endpoint does not require POST requests, resulting in a cross-site request forgery (CSRF) vulnerability.

As of publication of this advisory, there is no fix.

References

Affected packages

Maven / org.jenkins-ci.plugins:tag-profiler

org.jenkins-ci.plugins:tag-profiler

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0
Last affected
0.2

Affected versions

0.*

0.1
0.2