Description
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
Remediation
References
http://www.securityfocus.com/bid/101946
https://jenkins.io/security/advisory/2017-06-06/
Related Vulnerabilities
CVE-2023-1108 Vulnerability in maven package io.undertow:undertow-core
CVE-2022-2668 Vulnerability in maven package org.keycloak:keycloak-saml-core
CVE-2022-40635 Vulnerability in maven package org.craftercms:craftercms
CVE-2023-37950 Vulnerability in maven package com.mabl.integration.jenkins:mabl-integration