ZeroHour

CVE-2017-1000243

CVSS 3.0
4.3 medium
EPSS
<1%p48
Published
()
Modified
Description

Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites

Vendors
jenkins
Products
favorite plugin
Weakness
CWE-862
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.