Description
A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.java that allows attackers to stop tracking a resource.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-997
Related Vulnerabilities
CVE-2023-35887 Vulnerability in maven package org.apache.sshd:sshd-sftp
CVE-2022-36906 Vulnerability in maven package org.jenkins-ci.plugins:openshift-deployer
CVE-2022-2053 Vulnerability in maven package io.undertow:undertow-core
CVE-2023-34245 Vulnerability in npm package @udecode/plate-link
CVE-2014-3584 Vulnerability in maven package org.apache.cxf:cxf-rt-rs-security-xml