First published: Tue Mar 13 2018(Updated: )
An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in ``` OwnershipDescription.java, JobOwnerJobProperty.java, and OwnerNodeProperty.java ``` that allow an attacker with Job/Configure or Computer/Configure permission and without Ownership related permissions to override ownership metadata.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Job And Node Ownership | <=0.11.0 | |
maven/com.synopsys.jenkinsci:ownership | <0.12.0 | 0.12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.