Description
An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users with Overall/Read permission to read and write the Black Duck Hub plugin configuration.
Remediation
References
https://jenkins.io/security/advisory/2018-05-09/#SECURITY-670
Related Vulnerabilities
CVE-2015-2912 Vulnerability in maven package com.orientechnologies:orientdb-server
CVE-2023-30535 Vulnerability in maven package net.snowflake:snowflake-jdbc
CVE-2010-1330 Vulnerability in maven package org.jruby:jruby
CVE-2022-46907 Vulnerability in maven package org.apache.jspwiki:jspwiki-war
CVE-2023-28708 Vulnerability in maven package org.apache.tomcat:tomcat-catalina