Description
Jenkins Dependency Graph Viewer plugin 0.12 and earlier did not perform permission checks for the API endpoint that modifies the dependency graph, allowing anyone with Overall/Read permission to modify this data.
Remediation
References
https://jenkins.io/security/advisory/2017-10-23/
Related Vulnerabilities
CVE-2016-0782 Vulnerability in maven package org.apache.activemq:activemq-web-console
CVE-2020-2109 Vulnerability in maven package org.jenkins-ci.plugins.workflow:workflow-cps
CVE-2019-1003097 Vulnerability in maven package com.ds.tools.hudson:crowd
CVE-2023-24423 Vulnerability in maven package com.sonyericsson.hudson.plugins.gerrit:gerrit-trigger
CVE-2023-27987 Vulnerability in maven package org.apache.linkis:linkis-computation-client