GHSA-63jg-5wv6-7ghv
Dashboard / Vulnerabilities / GHSA-63jg-5wv6-7ghv
Summary: Jenkins Resource Disposer Plugin allows attacker to stop tracking specified resource
Details: A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.java that allows attackers to stop tracking a specified resource. Additionally, this API endpoint did not require POST requests, resulting in a CSRF vulnerability. As of version 0.12, this API endpoint requires POST requests and Overall/Administer permissions.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-1999037, https://github.com/jenkinsci/resource-disposer-plugin/commit/d826a99b06cc46c5dfadfd526b519ef0f65c8682, https://github.com/jenkinsci/resource-disposer-plugin, https://jenkins.io/security/advisory/2018-07-30/#SECURITY-997
Affected packages
Package
Name: org.jenkins-ci.plugins:resource-disposer
Purl: pkg:maven/org.jenkins-ci.plugins/resource-disposer
Affected ranges
Type: ECOSYSTEM
Events:
