First published: Fri Oct 17 2014(Updated: )
Jenkins before 1.502 allows remote authenticated users to configure an otherwise restricted project via vectors related to post-build actions.
Credit: security@debian.org security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Jenkins | <=1.501 | |
maven/org.jenkins-ci.main:jenkins-core | <1.480.3 | 1.480.3 |
maven/org.jenkins-ci.main:jenkins-core | >=1.481<1.502 | 1.502 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7330 is classified as a medium severity vulnerability.
To fix CVE-2013-7330, upgrade Jenkins to version 1.502 or later.
CVE-2013-7330 affects remote authenticated users who can configure restricted projects.
CVE-2013-7330 is present in Jenkins versions before 1.502.
CVE-2013-7330 allows unauthorized configuration changes to restricted projects, potentially compromising project integrity.