Description
A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.java that allows attackers to stop tracking a resource.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-997
Related Vulnerabilities
CVE-2022-37023 Vulnerability in maven package org.apache.geode:geode-core
CVE-2017-3162 Vulnerability in maven package org.apache.hadoop:hadoop-hdfs
CVE-2021-36161 Vulnerability in maven package org.apache.dubbo:dubbo-common
CVE-2023-46658 Vulnerability in maven package io.jenkins.plugins:teams-webhook-trigger
CVE-2019-0205 Vulnerability in maven package org.apache.thrift:libthrift