Description
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
Remediation
References
http://www.securityfocus.com/bid/101946
https://jenkins.io/security/advisory/2017-06-06/
Related Vulnerabilities
CVE-2022-33980 Vulnerability in maven package org.apache.commons:commons-configuration2
CVE-2016-4431 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2023-36469 Vulnerability in maven package org.xwiki.platform:xwiki-platform-notifications-ui
CVE-2019-16303 Vulnerability in npm package generator-jhipster-kotlin
CVE-2015-2156 Vulnerability in maven package io.netty:netty-all