Missing Permission Check Affecting net.hurstfrost.jenkins:avatar Open this link in a new tab package, versions [0,]
Attack Complexity
Low
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications-
snyk-id
SNYK-JAVA-NETHURSTFROSTJENKINS-458738
-
published
8 Aug 2019
-
disclosed
7 Aug 2019
-
credit
Oleg Nenashev
Introduced: 7 Aug 2019
CVE-2019-10377 Open this link in a new tabHow to fix?
There is no fixed version for net.hurstfrost.jenkins:avatar
.
Overview
net.hurstfrost.jenkins:avatar is a plugin that allows avatar images to be uploaded and associated with Jenkins users.
Affected versions of this package are vulnerable to Missing Permission Check that allows attackers with Overall/Read
access to change the avatar of any user of Jenkins.