Description
A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.java that allows attackers to stop tracking a resource.
Remediation
References
https://jenkins.io/security/advisory/2018-07-30/#SECURITY-997
Related Vulnerabilities
CVE-2010-1870 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2015-1808 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2017-1000242 Vulnerability in maven package org.jenkins-ci.plugins:git-client
CVE-2021-36161 Vulnerability in maven package org.apache.dubbo:dubbo-common
CVE-2022-40955 Vulnerability in maven package org.apache.inlong:sort-connector-mysql-cdc