GHSA-vv89-xggx-qqh2

    Dashboard / Vulnerabilities / GHSA-vv89-xggx-qqh2

    GHSA-vv89-xggx-qqh2

    Published: 24 May 2022Last Modified: 16 Feb 2024
    Aliases:

    Summary: Improper permission checks in Jenkins Copy Artifact Plugin

    Details: Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks when determining whether a build can copy artifacts from another project build. This allows attackers, usually with Job/Configure permission, to configure jobs to copy artifacts from jobs they have no permission to access. Copy Artifact Plugin 1.44 now properly performs permission checks when copying artifacts. When updating the plugin from a previous version, the previous behavior is retained (\"Migration mode\"). To enable the additional protections, switch to the new \"Production mode\". Doing so may cause existing jobs to fail to copy artifacts. For more information see the [plugin documentation](https://github.com/jenkinsci/copyartifact-plugin).

    Affected packages

    Package

    Name: org.jenkins-ci.plugins:copyartifact

    Purl: pkg:maven/org.jenkins-ci.plugins/copyartifact

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.44

    Affected versions

    1.13

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-vv89-xggx-qqh2 | CVE-DB