Description
An improper authorization vulnerability exists in Jenkins Google Play Android Publisher Plugin version 1.6 and earlier in GooglePlayBuildStepDescriptor.java that allow an attacker to obtain credential IDs.
Remediation
References
https://jenkins.io/security/advisory/2018-02-26/#SECURITY-715
Related Vulnerabilities
CVE-2017-12649 Vulnerability in maven package com.liferay:com.liferay.asset.browser.web
CVE-2024-4367 Vulnerability in maven package org.webjars.bower:pdfjs-dist
CVE-2020-14366 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2021-23267 Vulnerability in maven package org.craftercms:crafter-engine
CVE-2020-2128 Vulnerability in maven package com.catalogic.ecxjenkins:catalogic-ecx