Description
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
Remediation
References
http://www.securityfocus.com/bid/101946
https://jenkins.io/security/advisory/2017-06-06/
Related Vulnerabilities
CVE-2021-21607 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2022-41243 Vulnerability in maven package com.smalltest:smalltest
CVE-2020-14340 Vulnerability in maven package org.jboss.xnio:xnio-nio
CVE-2017-2650 Vulnerability in maven package cprice404:pipeline-classpath
CVE-2023-25500 Vulnerability in maven package com.vaadin:vaadin