Jenkins Request Rename Or Delete Plugin 1.1.0 and previous versions does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view an administrative configuration page listing pending requests.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
jenkins request rename or delete |