Description
A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.java that allows attackers to stop tracking a resource.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-997
Related Vulnerabilities
CVE-2020-2291 Vulnerability in maven package org.jenkins-ci.plugins:couchdb-statistics
CVE-2015-5172 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-login
CVE-2020-11023 Vulnerability in maven package org.webjars:jquery
CVE-2018-14642 Vulnerability in maven package io.undertow:undertow-core
CVE-2019-10429 Vulnerability in maven package org.jenkins-ci.plugins:gitlab-logo