Description
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
Remediation
References
http://www.securityfocus.com/bid/101946
https://jenkins.io/security/advisory/2017-06-06/
Related Vulnerabilities
CVE-2021-21122 Vulnerability in npm package electron
CVE-2022-23974 Vulnerability in maven package org.apache.pinot:pinot
CVE-2018-1000011 Vulnerability in maven package org.jvnet.hudson.plugins.findbugs:parent
CVE-2015-5170 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-login
CVE-2014-7839 Vulnerability in maven package org.jboss.resteasy:resteasy-jaxrs