Description
A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.java that allows attackers to stop tracking a resource.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-997
Related Vulnerabilities
CVE-2012-4431 Vulnerability in maven package org.apache.tomcat:catalina
CVE-2022-34802 Vulnerability in maven package org.jenkins-ci.plugins:rocketchatnotifier
CVE-2023-34036 Vulnerability in maven package org.springframework.hateoas:spring-hateoas
CVE-2022-22979 Vulnerability in maven package org.springframework.cloud:spring-cloud-function-parent
CVE-2023-33944 Vulnerability in maven package com.liferay.portal:release.portal.bom