Description
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
Remediation
References
http://www.securityfocus.com/bid/101946
https://jenkins.io/security/advisory/2017-06-06/
Related Vulnerabilities
CVE-2016-3506 Vulnerability in maven package com.oracle:ojdbc7
CVE-2014-0110 Vulnerability in maven package org.apache.cxf:cxf-rt-transports-http
CVE-2020-5397 Vulnerability in maven package org.springframework:spring-webflux
CVE-2023-37964 Vulnerability in maven package org.jenkins-ci.plugins:elasticbox