CVE-2023-30532

Missing Authorization in maven/org.jenkinsci.plugins.spoonscript/spoonscript

Identifiers

GHSA-7gqc-q9mc-6348, CVE-2023-30532

Package Slug

maven/org.jenkinsci.plugins.spoonscript/spoonscript

Vulnerability

Missing Authorization

Description

A missing permission check in Jenkins TurboScript Plugin 1.3 and earlier allows attackers with Item/Read permission to trigger builds of jobs corresponding to the attacker-specified repository.

Affected Versions

All versions up to 1.3

Solution

Unfortunately, there is no solution available yet.

Last Modified

2024-02-09

source