Description
Jenkins Dependency Graph Viewer plugin 0.12 and earlier did not perform permission checks for the API endpoint that modifies the dependency graph, allowing anyone with Overall/Read permission to modify this data.
Remediation
References
https://jenkins.io/security/advisory/2017-10-23/
Related Vulnerabilities
CVE-2017-5635 Vulnerability in maven package org.apache.nifi:nifi-framework-authorization
CVE-2022-34180 Vulnerability in maven package org.jenkins-ci.plugins:embeddable-build-status
CVE-2021-41184 Vulnerability in maven package org.webjars.bower:jquery-ui
CVE-2023-29215 Vulnerability in maven package org.apache.linkis:linkis-metadata-query-service-jdbc
CVE-2023-24453 Vulnerability in maven package org.jenkins-ci.plugins:testquality-updater