Description
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
Remediation
References
http://www.securityfocus.com/bid/101946
https://jenkins.io/security/advisory/2017-06-06/
Related Vulnerabilities
CVE-2017-12611 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2023-31453 Vulnerability in maven package org.apache.inlong:manager-web
CVE-2019-10201 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2023-26513 Vulnerability in maven package org.apache.sling:org.apache.sling.resourcemerger
CVE-2023-34459 Vulnerability in npm package @openzeppelin/contracts