Description
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
Remediation
References
https://jenkins.io/security/advisory/2017-06-06/
http://www.securityfocus.com/bid/101946
Related Vulnerabilities
CVE-2022-34211 Vulnerability in maven package org.jenkins-ci.plugins:vmware-vrealize-orchestrator
CVE-2023-40027 Vulnerability in npm package @keystone-6/core
CVE-2023-29212 Vulnerability in maven package org.xwiki.platform:xwiki-platform-panels-ui
CVE-2018-5382 Vulnerability in maven package org.bouncycastle:bcprov-jdk15
CVE-2020-17150 Vulnerability in npm package typescript-tslint-plugin