VDB
Sign up
MEDIUM5.3

GHSA-67v4-38h7-9jjp

Jenkins has a missing permission check, allowing users to obtain agent names

Quick fix

GHSA-67v4-38h7-9jjp — org.jenkins-ci.main:jenkins-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>2.516.3</version> for org.jenkins-ci.main:jenkins-core

Details

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission.

This allows attackers without Overall/Read permission to list agent names through its sidepanel executors widget.

Jenkins 2.528, LTS 2.516.3 removes the sidepanel from the affected view.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.jenkins-ci.main:jenkins-core
Introduced in: 0Fixed in: 2.516.3
Fix# pom.xml: bump <version>2.516.3</version> for org.jenkins-ci.main:jenkins-core
Maven/org.jenkins-ci.main:jenkins-core
Introduced in: 2.517Fixed in: 2.528
Fix# pom.xml: bump <version>2.528</version> for org.jenkins-ci.main:jenkins-core

References