Missing permission check in Jenkins Delete log Plugin
Moderate severity
GitHub Reviewed
Published
Nov 16, 2022
to the GitHub Advisory Database
•
Updated Oct 30, 2023
Package
Affected versions
<= 1.0
Patched versions
None
Description
Published by the National Vulnerability Database
Nov 15, 2022
Published to the GitHub Advisory Database
Nov 16, 2022
Reviewed
Dec 16, 2022
Last updated
Oct 30, 2023
A missing permission check in Jenkins Delete log Plugin 1.0 and earlier allows attackers with Item/Read permission to delete build logs. As of publication of this advisory, there is no fix.
References