Description
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
Remediation
References
http://www.securityfocus.com/bid/101946
https://jenkins.io/security/advisory/2017-06-06/
Related Vulnerabilities
CVE-2023-29529 Vulnerability in npm package matrix-js-sdk
CVE-2017-1000393 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2013-4940 Vulnerability in npm package yui
CVE-2023-43795 Vulnerability in maven package org.geoserver.extension:gs-wps-core
CVE-2019-1003006 Vulnerability in maven package org.jenkins-ci.plugins:groovy