Advisories for Maven/Io.jenkins.plugins/Benchmark-Evaluator package

2023

Missing Authorization

A missing permission check in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL and to check for the existence of directories, .csv, and .ycsb files on the Jenkins controller file system.