The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-11-25 11:55
Updated : 2016-07-15 07:59
NVD link : CVE-2013-6373
Mitre link : CVE-2013-6373
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
jenkins-ci
- exclusion