GHSA-9mc6-vgmq-x6xf
Dashboard / Vulnerabilities / GHSA-9mc6-vgmq-x6xf
Summary: Lack of authentication mechanism in Jenkins DotCi Plugin webhook
Details: DotCi Plugin provides a webhook endpoint at `/githook/` that can be used to trigger builds of the job for a GitHub repository. In DotCi Plugin 2.40.00 and earlier, this endpoint can be accessed without authentication. This allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits. This plugin has been suspended.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-41238, https://github.com/jenkinsci/DotCi, https://plugins.jenkins.io/DotCi, https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2867, https://www.jenkins.io/security/plugins/#suspensions
Affected packages
Package
Name: com.groupon.jenkins-ci.plugins:DotCi
Purl: pkg:maven/com.groupon.jenkins-ci.plugins/DotCi
Affected ranges
Type: ECOSYSTEM
Events:
