Improper Authorization Affecting org.jenkins-ci.plugins:gitlab-oauth package, versions [,1.6)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.09% (42nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGJENKINSCIPLUGINS-584904
  • published16 Jul 2020
  • disclosed16 Jul 2020
  • creditUnknown

Introduced: 16 Jul 2020

CVE-2020-2228  (opens in a new tab)
CWE-285  (opens in a new tab)

How to fix?

Upgrade org.jenkins-ci.plugins:gitlab-oauth to version 1.6 or higher.

Overview

org.jenkins-ci.plugins:gitlab-oauth is an a plugin for offloading authentication and authorization to GitLab.

Affected versions of this package are vulnerable to Improper Authorization does not differentiate between user names and hierarchical group names when performing authorization. This allows an attacker with permissions to create groups in GitLab to gain the privileges granted to another user or group.Gitlab Authentication Plugin 1.6 performs user name and group name authorization checks using the appropriate GitLab APIs.

CVSS Scores

version 3.1