Jenkins Exclusion Plugin allows Access to Resource Locks
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Mar 13, 2025
Description
Published by the National Vulnerability Database
Nov 25, 2013
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Mar 13, 2025
Last updated
Mar 13, 2025
The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.
References