Description
A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.java that allows attackers to stop tracking a resource.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-997
Related Vulnerabilities
CVE-2021-21608 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-44794 Vulnerability in maven package cn.dev33:sa-token-core
CVE-2019-10316 Vulnerability in maven package org.jenkins-ci.plugins:aqua-microscanner
CVE-2023-46131 Vulnerability in maven package org.grails:grails-databinding
CVE-2010-3718 Vulnerability in maven package tomcat:catalina