GHSA-mrf6-4gw6-65v3
Dashboard / Vulnerabilities / GHSA-mrf6-4gw6-65v3
Summary: Jenkins extreme-feedback Plugin vulnerable to Missing Authorization
Details: Jenkins extreme-feedback Plugin 1.7 and earlier does not perform a permission check in an HTTP endpoint. This allows attackers with Overall/Read permission to discover information about job names attached to lamps, discover MAC and IP addresses of existing lamps, and rename lamps. As of publication of this advisory, there is no fix.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-41242, https://github.com/jenkinsci/extreme-feedback-plugin, https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2001
Affected packages
Package
Name: org.jenkins-ci.plugins:extreme-feedback
Purl: pkg:maven/org.jenkins-ci.plugins/extreme-feedback
Affected ranges
Type: ECOSYSTEM
Events:
